Impact
The NetBox Device Type Library allows unauthenticated contributors to inject and execute arbitrary Python modules by taking advantage of the missing tests/__init__.py file and the default pytest import precedence. When a pull‑request contains a "tests" directory, pytest adds it to the front of sys.path during collection, causing imports from this directory to shadow legitimate libraries such as "GitPython". The module, for example "tests/git.py", runs immediately when the test runner imports "GitPython", giving the contributor full control of the GitHub Actions runner. The result is remote code execution, with the attacker able to tamper with test results, exfiltrate secrets, or run arbitrary code. In addition, an unfixed NETBOX_DT_LIBRARY_URL reference can be abused for Server Side Request Forgery, allowing reading of cloud metadata and theft of credentials. This flaw aligns with CWE-427 and CWE-829.
Affected Systems
Affected systems are any deployments that incorporate the netbox-community/devicetype-library repository prior to the regression-fix commit b0d9a3da. The fix is applied in that commit and all subsequent releases. The vulnerability is present in all earlier releases, regardless of version number, so any instance of the library that has not applied the patch is vulnerable.
Risk and Exploitability
The CVSS base score of 8.8 indicates a high severity, and the EPSS score of less than 1% shows that exploitation attempts are currently very rare. The vulnerability is not listed in the CISA KEV catalogue. The attack vector is primarily via the repository contribution workflow; an unauthenticated contributor can create a pull request and thereby inject malicious modules. With the SSRF vector, a compromised or malicious author can also abuse the library's URL handling to reach internal services. Because the exploit requires interaction with the CI environment, the risk to production systems is mitigated if the library is only used locally, but environments that automatically import or scan the repository are at risk.
OpenCVE Enrichment