Code Execution Vulnerability in NetBox Device Type Library by NetBox
CVE-2026-55251
6.5MEDIUM
What is CVE-2026-55251?
The NetBox Device Type Library contains a vulnerability that allows potential code execution via unauthorized modifications in pull requests. Prior to specific security updates, contributors could alter files essential for the CI workflow, enabling unvetted code to execute on the CI runner during pull requests. This behavior posed significant security risks, as individuals without special repository permissions could manipulate these files, leading to unauthorized actions. The issue was addressed in commit f41fc1e, enhancing the review and execution processes for submitted code.
Affected Version(s)
devicetype-library < f41fc1e48dec8d7d31afba5f13a8c73652ff5796
