DescriptionLibreNMS versions prior to 26.2.0 contain a stored cross-site scripting (XSS) vulnerability in the /port-groups endpoint. The name parameter supplied when creating a port group is not properly sanitized and is later embedded in the Delete button’s onclick handler, allowing injection of arbitrary JavaScript. An authenticated administrator can exploit this issue to execute malicious scripts in another user’s browser, leading to session hijacking or other actions performed with the victim’s privileges.