Code Execution Vulnerability in NetBox Device Type Library by NetBox
CVE-2026-54916
8.8HIGH
What is CVE-2026-54916?
The NetBox Device Type Library allows for community-sourced definitions but contains a vulnerability that could allow an unauthenticated attacker to execute arbitrary code. An attacker can leverage the missing tests/init.py and incorrect import mode configuration to shadow existing modules, leading to unauthorized execution during testing phases. This flaw enables manipulation of test results and access to sensitive tokens or network resources, posing significant security risks. The vulnerability has been addressed in a recent commit.
Affected Version(s)
devicetype-library < b0d9a3dadd0a0a9d3c93b0b2777559fd4bad1037g
