User Authentication Lapse in Nautobot Network Automation Platform
CVE-2025-49143
What is CVE-2025-49143?
Nautobot, a Network Source of Truth and Network Automation Platform, contains a vulnerability that allows unauthorized access to files uploaded by users to its MEDIA_ROOT directory. Specifically, prior to versions 2.4.10 and 1.6.32, images related to DeviceTypes and other entities could be accessed directly without proper user authentication. This flaw poses a significant risk, as anonymous users might exploit this issue to retrieve sensitive files simply by knowing or guessing the URL. Versions 2.4.10 and 1.6.32 have addressed this security gap by ensuring user authentication checks are enforced on the endpoint serving these files.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
nautobot < 1.6.32 < 1.6.32
nautobot >= 2.0.0, < 2.4.10 < 2.0.0, 2.4.10
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
