Stored Cross-Site Scripting in Nautobot Network Automation Platform
CVE-2026-83801
5.4MEDIUM
What is CVE-2026-83801?
The Nautobot Network Automation Platform is vulnerable to stored Cross-Site Scripting (XSS) due to improper handling of user input in relationship descriptions and module family names. Malicious users with certain permissions can inject HTML or JavaScript code, which is then executed in the browsers of authenticated users, including administrators and superusers. This allows attackers to hijack sessions, steal tokens, and potentially escalate privileges. The issue has been addressed in Nautobot versions 2.4.37 and 3.1.8, which users are advised to upgrade to in order to mitigate this risk.
Affected Version(s)
nautobot < 2.4.37 < 2.4.37
nautobot >= 3.0.0, < 3.1.8 < 3.0.0, 3.1.8
