Reflected Cross-Site Scripting Vulnerability in LibreNMS Network Monitoring Tool
CVE-2025-65013

6.2MEDIUM

Key Information:

Vendor

Librenms

Status
Vendor
CVE Published:
18 November 2025

What is CVE-2025-65013?

LibreNMS, a popular network monitoring tool that utilizes PHP, MySQL, and SNMP, has been found to contain a reflected cross-site scripting vulnerability. This issue lives within the /maps/nodeimage endpoint, where the Image Name parameter is reflected in the application’s HTTP response without appropriate output encoding or sanitization. As a result, malicious actors can design a URL that executes arbitrary JavaScript in the browser of a targeted user when accessed. This vulnerability has been remedied in version 25.11.0 of LibreNMS.

Affected Version(s)

librenms < 25.11.0

References

CVSS V3.1

Score:
6.2
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.