Description
NetBox versions 2.9.5 before 4.7.0 contain a server-side template injection vulnerability that allows a low-privileged user with the "Can add custom links" permission to steal session cookies and API tokens of other users by exposing the raw Django HttpRequest object to the Jinja2 template context. Attackers can craft a custom link template embedding request.COOKIES['sessionid'] or a user's API token into an img src URL, which bypasses the clean_html sanitizer and auto-exfiltrates the victim's credentials to an attacker-controlled host when a privileged user views the object, enabling full account takeover.
Published: 2026-10-06
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: Session hijacking leading to account takeover
Action: Immediate Patch
AI Analysis

Impact

A server‑side template injection in NetBox allows a low‑privileged user with the "Can add custom links" permission to embed the raw Django HttpRequest object into a custom link. By inserting request.COOKIES['sessionid'] or an authenticated API token into an image source tag, the attacker can force the victim’s session cookie or API token to be sent to an attacker‑controlled host when a privileged user views the link, enabling full account takeover. The weakness is represented by CWE-668 and CWE-79.

Affected Systems

NetBox Community Edition versions 2.9.5 through any release before 4.7.0 are affected. The issue applies to all installations that expose custom link templates in these releases. Upgrading to 4.7.0 or later removes the vulnerability.

Risk and Exploitability

With a CVSS score of 6.9 the vulnerability is considered medium severity. No EPSS data is publicly available and the issue is not listed in the CISA KEV catalog. Exploitation requires a low‑privileged user to craft a malicious custom link and a privileged user to view it; if privileged users routinely interact with custom links created by others, the attack can be performed without additional privileges, making the risk significant for organizations with many active accounts.

Generated by OpenCVE AI on October 6, 2026 at 21:02 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade NetBox to version 4.7.0 or later to remove the template‑injection flaw.
  • Revoke the "Can add custom links" permission from any users who do not need it.
  • Disable or restrict the custom link functionality until the vulnerability is fixed.
  • Implement network monitoring to block outbound requests from the NetBox server to untrusted external hosts, mitigating credential exfiltration.

Generated by OpenCVE AI on October 6, 2026 at 21:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 19:00:00 +0000

Type Values Removed Values Added
Description NetBox versions 2.9.5 before 4.7.0 contain a server-side template injection vulnerability that allows a low-privileged user with the "Can add custom links" permission to steal session cookies and API tokens of other users by exposing the raw Django HttpRequest object to the Jinja2 template context. Attackers can craft a custom link template embedding request.COOKIES['sessionid'] or a user's API token into an img src URL, which bypasses the clean_html sanitizer and auto-exfiltrates the victim's credentials to an attacker-controlled host when a privileged user views the object, enabling full account takeover.
Title NetBox 2.9.5 < 4.7.0 Session Hijacking via Custom Links
Weaknesses CWE-668
CWE-79
References
Metrics cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:N/VA:N/SC:L/SI:L/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-06T18:50:28.326Z

Reserved: 2026-10-01T18:02:50.083Z

Link: CVE-2026-104073

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-06T19:17:40.143

Modified: 2026-10-06T20:05:55.733

Link: CVE-2026-104073

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T21:15:06Z

Weaknesses
  • CWE-668

    Exposure of Resource to Wrong Sphere

  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')