CVE-2025-68614: LibreNMS Alert Rule API Cross-Site Scripting Vulnerability

Published Dec 22, 2025
·
Updated

LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Prior to version 25.12.0, the Alert Rule API is vulnerable to stored cross-site scripting. Alert rules can be created or updated via LibreNMS API. The alert rule name is not properly sanitized, and can be used to inject HTML code. This issue has been patched in version 25.12.0.

Other sources

Please find POC file here https://trendmicro-my.sharepoint.com/:u:/p/kholoudaltookhy/IQCfcnOE5ykQSb6Fm-HFI872AZzeIJxU-3aDk0jheXNE?e=zkN76d

ZDI-CAN-28575: LibreNMS Alert Rule API Cross-Site Scripting Vulnerability

-- CVSS -----------------------------------------

4.3: AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:L

-- ABSTRACT -------------------------------------

Trend Micro's Zero Day Initiative has identified a vulnerability affecting the following products: LibreNMS - LibreNMS

-- VULNERABILITY DETAILS ------------------------ Version tested: 25.10.0 Installer file: NA Platform tested: NA

---

Analysis

LibreNMS Alert Rule API Stored Cross-Site Scripting

Overview Alert rules can be created or updated via LibreNMS API. The alert rule name is not properly sanitized, and can be used to inject HTML code.

Affected versions The latest version at the time of writing (25.10.0) is vulnerable.

Root cause When an alert rule is created or updated via the API, function addeditrule() in includes/html/apifunctions.inc.php is called to add/update the entry in the database. When an alert rule is created via the web interface, HTML tags are stripped from the rule name, however this is not the case when using the API.

As such, it is possible to create an alert rule where the name is: <script>alert(1)</script>

Later, when a victim browses to the Alerts > Alert Rule page, PHP script\xc2\xa0includes/html/print-alert/rules.php\xc2\xa0is called. It notably includes the file\xc2\xa0includes/html/modal/alertrulelist.inc.php, which returns HTML code for a modal window that searches alert rules.

The modal window includes an HTML table with all rules, including their name, and an inline JavaScript that calls the\xc2\xa0bootgrid()\xc2\xa0function (http://www.jquery-bootgrid.com/) for styling and enhancing the table.

alertrule.list.inc.php sanitizes the rule name with the function e() before including it in the table, which XML encodes all special characters. However the\xc2\xa0bootgrid()\xc2\xa0function rewrites the table cells content when enhancing the table, and as a side effect, XML character references are decoded. After the script updated the table, the browser now interprets the payload as HTML tags and includes the code to the DOM.

Detection guidance - inspect HTTP POST and PUT requests to a Request-URI that includes the string\xc2\xa0/api/v0/rules - check if the\xc2\xa0name\xc2\xa0JSON value includes a < character

PoC The proof-of-concept can be run as such: python3 poc.py ipaddr -T <token>

-- CREDIT --------------------------------------- This vulnerability was discovered by: Simon Humbert of Trend Research of Trend Micro

-- FURTHER DETAILS ------------------------------

Supporting files:

If supporting files were contained with this report they are provided within a password protected ZIP file. The password is the ZDI candidate number in the form: ZDI-CAN-XXXX where XXXX is the ID number.

Please confirm receipt of this report. We expect all vendors to remediate ZDI vulnerabilities within 120 days of the reported date. If you are ready to release a patch at any point leading up to the deadline, please coordinate with us so that we may release our advisory detailing the issue. If the 120-day deadline is reached and no patch has been made available we will release a limited public advisory with our own mitigations, so that the public can protect themselves in the absence of a patch. Please keep us updated regarding the status of this issue and feel free to contact us at any time:

Zero Day Initiative zdi-disclosures@trendmicro.com

The PGP key used for all ZDI vendor communications is available from:

http://www.zerodayinitiative.com/documents/disclosures-pgp-key.asc

-- INFORMATION ABOUT THE ZDI -------------------- Established by TippingPoint and acquired by Trend Micro, the Zero Day Initiative (ZDI) neither re-sells vulnerability details nor exploit code. Instead, upon notifying the affected product vendor, the ZDI provides its Trend Micro TippingPoint customers with zero day protection through its intrusion prevention technology. Explicit details regarding the specifics of the vulnerability are not exposed to any parties until an official vendor patch is publicly available.

Please contact us for further details or refer to:

http://www.zerodayinitiative.com

-- DISCLOSURE POLICY ----------------------------

Our vulnerability disclosure policy is available online at:

http://www.zerodayinitiative.com/advisories/disclosurepolicy/

GitHub

Affected Software

3 affected componentsFixes available
librenms librenms<25.12.0
composer/librenms/librenms<25.12.0
25.12.0
librenms librenms<25.12.0

Event History

Dec 22, 2025
CVE Published
via MITRE·11:43 PM
Data Sourced
via MITRE·11:43 PM
DescriptionSeverityWeakness
Dec 23, 2025
Data Sourced
via NVD·12:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Advisory Published
via GitHub·06:19 PM
Data Sourced
via GitHub·06:19 PM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-68614?

CVE-2025-68614 is classified as a medium severity vulnerability due to its potential for stored cross-site scripting in LibreNMS.

2

How does CVE-2025-68614 affect users?

CVE-2025-68614 can allow attackers to inject malicious scripts into alert rule names, potentially compromising user sessions and sensitive information.

3

How do I fix CVE-2025-68614?

To fix CVE-2025-68614, upgrade to LibreNMS version 25.12.0 or later, which contains the necessary security patches.

4

What software versions are affected by CVE-2025-68614?

CVE-2025-68614 affects LibreNMS versions prior to 25.12.0.

5

Is there a way to mitigate CVE-2025-68614 without upgrading?

Mitigating CVE-2025-68614 without upgrading is not recommended due to the complexity of properly sanitizing inputs in the application.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203