Description
NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox. The absence of tests/init.py and the lack of --import-mode=importlib cause pytest prepend import mode to place the tests directory at the front of sys.path during collection. An unauthenticated contributor can add a module such as tests/git.py that shadows GitPython when tests/definitions_test.py executes from git import Git, Repo, or add tests/conftest.py for automatic collection-time execution. Python imports and runs the pull-request module before any test function, allowing arbitrary code execution on the GitHub Actions runner, test-result tampering, and access to tokens or network resources exposed to the workflow. This module-shadowing path is independent of the earlier pickle deserialization flaw and the separately tracked NETBOX_DT_LIBRARY_URL issue. This vulnerability is fixed by commit b0d9a3dadd0a0a9d3c93b0b2777559fd4bad1037.
Published: 2026-09-17
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The NetBox Device Type Library allows unauthenticated contributors to inject and execute arbitrary Python modules by taking advantage of the missing tests/__init__.py file and the default pytest import precedence. When a pull‑request contains a "tests" directory, pytest adds it to the front of sys.path during collection, causing imports from this directory to shadow legitimate libraries such as "GitPython". The module, for example "tests/git.py", runs immediately when the test runner imports "GitPython", giving the contributor full control of the GitHub Actions runner. The result is remote code execution, with the attacker able to tamper with test results, exfiltrate secrets, or run arbitrary code. In addition, an unfixed NETBOX_DT_LIBRARY_URL reference can be abused for Server Side Request Forgery, allowing reading of cloud metadata and theft of credentials. This flaw aligns with CWE-427 and CWE-829.

Affected Systems

Affected systems are any deployments that incorporate the netbox-community/devicetype-library repository prior to the regression-fix commit b0d9a3da. The fix is applied in that commit and all subsequent releases. The vulnerability is present in all earlier releases, regardless of version number, so any instance of the library that has not applied the patch is vulnerable.

Risk and Exploitability

The CVSS base score of 8.8 indicates a high severity, and the EPSS score of less than 1% shows that exploitation attempts are currently very rare. The vulnerability is not listed in the CISA KEV catalogue. The attack vector is primarily via the repository contribution workflow; an unauthenticated contributor can create a pull request and thereby inject malicious modules. With the SSRF vector, a compromised or malicious author can also abuse the library's URL handling to reach internal services. Because the exploit requires interaction with the CI environment, the risk to production systems is mitigated if the library is only used locally, but environments that automatically import or scan the repository are at risk.

Generated by OpenCVE AI on September 19, 2026 at 02:58 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the devicetype-library to the fixed commit (b0d9a3da) or a newer release that incorporates the patch.
  • Add a minimal tests/__init__.py file or configure pytest to use import-mode=importlib to prevent the test directory from taking precedence during import.
  • Restrict pull‑request contributions to trusted maintainers or enforce mandatory code review that checks for rogue modules in the tests directory.
  • Harden NETBOX_DT_LIBRARY_URL by validating or whitelisting URLs and preventing external redirects to avoid SSRF.
  • Monitor the CI environment for unexpected code execution or repeated failed executions that may indicate a compromise.

Generated by OpenCVE AI on September 19, 2026 at 02:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Netbox-community
Netbox-community devicetype-library
Vendors & Products Netbox-community
Netbox-community devicetype-library
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Description NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox. The absence of tests/init.py and the lack of --import-mode=importlib cause pytest prepend import mode to place the tests directory at the front of sys.path during collection. An unauthenticated contributor can add a module such as tests/git.py that shadows GitPython when tests/definitions_test.py executes from git import Git, Repo, or add tests/conftest.py for automatic collection-time execution. Python imports and runs the pull-request module before any test function, allowing arbitrary code execution on the GitHub Actions runner, test-result tampering, and access to tokens or network resources exposed to the workflow. This module-shadowing path is independent of the earlier pickle deserialization flaw and the separately tracked NETBOX_DT_LIBRARY_URL issue. This vulnerability is fixed by commit b0d9a3dadd0a0a9d3c93b0b2777559fd4bad1037.
Title NetBox Device Type Library: Module Shadowing Bypass of prior pickle fix - RCE via missing `tests/__init__.py` + SSRF via unfixed `NETBOX_DT_LIBRARY_URL` → Cloud Metadata credential theft
Weaknesses CWE-427
CWE-829
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Netbox-community Devicetype-library
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-18T18:33:16.921Z

Reserved: 2026-06-16T13:49:33.556Z

Link: CVE-2026-54916

cve-icon Vulnrichment

Updated: 2026-09-18T17:24:11.220Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T21:17:17.790

Modified: 2026-09-24T21:25:27.050

Link: CVE-2026-54916

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T03:00:13Z

Weaknesses
  • CWE-427

    Uncontrolled Search Path Element

  • CWE-829

    Inclusion of Functionality from Untrusted Control Sphere