Vulnerability in NetBox Device Type Library Affects Data Integrity and Security
CVE-2026-54918

5.3MEDIUM

Key Information:

Vendor
CVE Published:
17 September 2026

What is CVE-2026-54918?

The NetBox Device Type Library allows unauthenticated users to manipulate the NETBOX_DT_LIBRARY_URL constant in specific repository revisions, potentially causing sensitive data exposure and integrity issues. When tests are executed via pytest, the manipulated URL can trigger unauthorized Git smart-HTTP requests to external hosts, enabling attackers to load potentially harmful JSON validation caches. This breach compromises the internal validation mechanism, risking data uniqueness checks. A patch has been issued to rectify this issue.

Affected Version(s)

devicetype-library < 8980c690097e92f5028c7e6df402b327d827ecd5

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.