Impact
The NetBox Device Type Library test harness imports files via pickle.load, allowing arbitrary code to run during deserialization. A malicious pull request can supply crafted pickle files that execute code with the privileges of the test runner or maintainer process, compromising confidentiality, integrity, and availability of the environment in which the tests are executed.
Affected Systems
netbox-community:devicetype-library
Risk and Exploitability
The vulnerability carries a CVSS score of 9.6, indicating critical severity, while the EPSS score is below 1%, suggesting low current exploitation probability. It is not listed in the CISA KEV catalog. The likely attack vector involves an unauthenticated contributor creating a pull request that contains a malicious pickle file; when the test suite runs, the pickle is deserialized, triggering arbitrary code execution in the CI or maintainer environment.
OpenCVE Enrichment