MEDIUM 5.3 NVD
CVE-2026-84191
LibreNMS before 26.5.0 contains stored cross-site scripting vulnerabilities in VRF display pages where mplsVpnVrfDescription, vrf_name, and mplsVpnVrfRouteDisti
LibreNMS before 26.5.0 contains stored cross-site scripting vulnerabilities in VRF display pages where mplsVpnVrfDescription, vrf_name, and mplsVpnVrfRouteDistinguisher fields from SNMP polling are rendered without sanitization. Attackers controlling a monitored network device can inject arbitrary JavaScript through SNMP responses that executes in the browser of any user viewing VRF-related pages.
References
- https://github.com/librenms/librenms/security/advisories/GHSA-g993-wffj-m3gv
- https://www.vulncheck.com/advisories/librenms-before-26.5.0-stored-xss-via-snmp-vrf-fields
This medium severity vulnerability with a CVSS score of 5.3 was published on 2026-09-01 via NVD.
vulnfeed aggregates 11474 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.