Code Execution Vulnerability in NetBox Device Type Library by NetBox
CVE-2026-54916

8.8HIGH

Key Information:

Vendor
CVE Published:
17 September 2026

What is CVE-2026-54916?

The NetBox Device Type Library allows for community-sourced definitions but contains a vulnerability that could allow an unauthenticated attacker to execute arbitrary code. An attacker can leverage the missing tests/init.py and incorrect import mode configuration to shadow existing modules, leading to unauthorized execution during testing phases. This flaw enables manipulation of test results and access to sensitive tokens or network resources, posing significant security risks. The vulnerability has been addressed in a recent commit.

Affected Version(s)

devicetype-library < b0d9a3dadd0a0a9d3c93b0b2777559fd4bad1037g

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.