THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-7gww-x7fh-jf9j (high) — LibreNMS: SSRF-driven stored XSS via Oxidized API response fields in device showconfig page

[GHSA] GHSA-7gww-x7fh-jf9j (high) — LibreNMS: SSRF-driven stored XSS via Oxidized API response fields in device showconfig page

medgithub_advisoriesPublished 2026-08-18

GHSA-7gww-x7fh-jf9j Severity: high CVE: None

LibreNMS: SSRF-driven stored XSS via Oxidized API response fields in device showconfig page

### Summary The Oxidized integration URL (`oxidized.url`) is admin-configurable. LibreNMS fetches device info and version history from that URL and renders JSON fields (`name`, `ip`, `model`, `author`, commit message) into HTML without `htmlspecialchars()`. An

Original source: https://github.com/advisories/GHSA-7gww-x7fh-jf9j