CVE-2025-68614 MEDIUM

CVE-2025-68614: LibreNMS Alert Rule API Cross-Site Scripting Vulnerability

Vendor Librenms
Product librenms
Weakness CWE-79 · XSS
Published December 22, 2025
Last update December 22, 2025

CVSS base score

4.3/10
Attack vector Network
Attack complexity Low
Privileges required High
User interaction Required
Confidentiality Low
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:L

What the vulnerability does

01Description

LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Prior to version 25.12.0, the Alert Rule API is vulnerable to stored cross-site scripting. Alert rules can be created or updated via LibreNMS API. The alert rule name is not properly sanitized, and can be used to inject HTML code. This issue has been patched in version 25.12.0.

Key dates

02Disclosure timeline

December 22, 2025 CVE published
December 22, 2025 Record updated

Related vulnerabilities

04Related CVE