Vulnerability in NetBox Device Type Library Affects Data Integrity and Security
CVE-2026-54918
5.3MEDIUM
What is CVE-2026-54918?
The NetBox Device Type Library allows unauthenticated users to manipulate the NETBOX_DT_LIBRARY_URL constant in specific repository revisions, potentially causing sensitive data exposure and integrity issues. When tests are executed via pytest, the manipulated URL can trigger unauthorized Git smart-HTTP requests to external hosts, enabling attackers to load potentially harmful JSON validation caches. This breach compromises the internal validation mechanism, risking data uniqueness checks. A patch has been issued to rectify this issue.
Affected Version(s)
devicetype-library < 8980c690097e92f5028c7e6df402b327d827ecd5
