Description
NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox. The validation test harness can deserialize pull-request-controlled tracked pickle cache files through pickle.load in the read_pickle_data function in tests/pickle_operations.py. An unauthenticated contributor can change USE_LOCAL_KNOWN_SLUGS in tests/test_configuration.py and supply a crafted tests/known-modules.pickle or tests/known-racks.pickle file that tests/definitions_test.py loads when pytest runs. Deserialization invokes attacker-controlled object reduction behavior, allowing arbitrary code execution in the GitHub Actions runner or in a maintainer process that runs the tests, with the confidentiality, integrity, and availability of reachable resources at risk. This vulnerability is fixed with commit 1c6f7e2b93589b965318c6e67ac3504831f0e71e.
Published: 2026-09-17
Score: 9.6 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The NetBox Device Type Library test harness imports files via pickle.load, allowing arbitrary code to run during deserialization. A malicious pull request can supply crafted pickle files that execute code with the privileges of the test runner or maintainer process, compromising confidentiality, integrity, and availability of the environment in which the tests are executed.

Affected Systems

netbox-community:devicetype-library

Risk and Exploitability

The vulnerability carries a CVSS score of 9.6, indicating critical severity, while the EPSS score is below 1%, suggesting low current exploitation probability. It is not listed in the CISA KEV catalog. The likely attack vector involves an unauthenticated contributor creating a pull request that contains a malicious pickle file; when the test suite runs, the pickle is deserialized, triggering arbitrary code execution in the CI or maintainer environment.

Generated by OpenCVE AI on September 19, 2026 at 02:59 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update netbox-community/devicetype-library to a version that includes the fix (commit 1c6f7e2b93589b965318c6e67ac3504831f0e71e).
  • Modify the test suite to disable or remove pickle.load usage, such as deleting the tests/known-modules.pickle and tests/known-racks.pickle files or configuring tests to skip pickle deserialization.
  • Enforce stricter code review for pull requests and run CI test environments with minimal privileges or isolated runners to limit the impact of potential exploitation.

Generated by OpenCVE AI on September 19, 2026 at 02:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Netbox-community
Netbox-community devicetype-library
Vendors & Products Netbox-community
Netbox-community devicetype-library

Thu, 17 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
Description NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox. The validation test harness can deserialize pull-request-controlled tracked pickle cache files through pickle.load in the read_pickle_data function in tests/pickle_operations.py. An unauthenticated contributor can change USE_LOCAL_KNOWN_SLUGS in tests/test_configuration.py and supply a crafted tests/known-modules.pickle or tests/known-racks.pickle file that tests/definitions_test.py loads when pytest runs. Deserialization invokes attacker-controlled object reduction behavior, allowing arbitrary code execution in the GitHub Actions runner or in a maintainer process that runs the tests, with the confidentiality, integrity, and availability of reachable resources at risk. This vulnerability is fixed with commit 1c6f7e2b93589b965318c6e67ac3504831f0e71e.
Title NetBox Device Type Library: Insecure Pickle Deserialization in Test Suite Allows Remote Code Execution via Malicious Pull Request
Weaknesses CWE-502
CWE-829
References
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}


Subscriptions

Netbox-community Devicetype-library
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-21T21:11:24.708Z

Reserved: 2026-06-15T23:12:41.965Z

Link: CVE-2026-54752

cve-icon Vulnrichment

Updated: 2026-09-21T21:11:20.590Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T20:16:52.877

Modified: 2026-09-24T21:25:27.050

Link: CVE-2026-54752

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T03:00:13Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data

  • CWE-829

    Inclusion of Functionality from Untrusted Control Sphere