CVE-2025-62411 - CVE House
Back to Database
Status published Medium CVE-2025-62411

Stored XSS in Alert Transport name field in LibreNMS

Vulnerability Description

LibreNMS is a community-based GPL-licensed network monitoring system. LibreNMS <= 25.8.0 contains a Stored Cross-Site Scripting (XSS) vulnerability in the Alert Transports management functionality. When an administrator creates a new Alert Transport, the value of the Transport name field is stored and later rendered in the Transports column of the Alert Rules page without proper input validation or output encoding. This leads to arbitrary JavaScript execution in the admin’s browser. This vulnerability is fixed in 25.10.0.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-62411

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

librenms
Vulnerable Versions:
< 25.10.0

Timeline

Official Publish: October 16th, 2025
Last Modified: October 16th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N

Weaknesses (CWE)