Code Execution Vulnerability in NetBox Device Type Library by NetBox
CVE-2026-55251

6.5MEDIUM

Key Information:

Vendor
CVE Published:
1 October 2026

What is CVE-2026-55251?

The NetBox Device Type Library contains a vulnerability that allows potential code execution via unauthorized modifications in pull requests. Prior to specific security updates, contributors could alter files essential for the CI workflow, enabling unvetted code to execute on the CI runner during pull requests. This behavior posed significant security risks, as individuals without special repository permissions could manipulate these files, leading to unauthorized actions. The issue was addressed in commit f41fc1e, enhancing the review and execution processes for submitted code.

Affected Version(s)

devicetype-library < f41fc1e48dec8d7d31afba5f13a8c73652ff5796

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.