Deserialization Vulnerability in NetBox Device Type Library
CVE-2026-54752
9.6CRITICAL
What is CVE-2026-54752?
The NetBox Device Type Library allows unauthenticated contributors to exploit a deserialization vulnerability through manipulated pickle files. This flaw can lead to arbitrary code execution during pytest runs, potentially compromising the confidentiality, integrity, and availability of valuable resources. The vulnerability arises from an oversight in the validation mechanisms within the read_pickle_data function. It is crucial for users to update and secure their systems against this risk to prevent unauthorized access and safeguard sensitive data.
Affected Version(s)
devicetype-library < 1c6f7e2b93589b965318c6e67ac3504831f0e71e
