Description
NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox. In the affected repository revisions, NETBOX_DT_LIBRARY_URL in tests/test_configuration.py is a free-form tracked constant that an unauthenticated pull-request author can change before the validation test harness runs. During pytest collection, tests/definitions_test.py passes the value to Repo.clone_from and create_remote("upstream").fetch(), causing blind Git smart-HTTP requests to an attacker-selected host or loading attacker-controlled tests/known-*.json validation caches. The blind request cannot set arbitrary metadata-service headers or return response bodies, and this path does not execute remote Git hooks, but substituted known data can bypass slug, module, and rack uniqueness validation. This vulnerability is fixed in commit 8980c690097e92f5028c7e6df402b327d827ecd5.
Published: 2026-09-17
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Integrity Bypass via SSRF and test data substitution
Action: Apply Patch
AI Analysis

Impact

The vulnerability arises from a free‑form constant, NETBOX_DT_LIBRARY_URL, that can be modified by an unauthenticated pull‑request author before the test harness runs. During pytest collection the value is passed to Repo.clone_from and create_remote('upstream').fetch(), forcing blind Git smart‑HTTP requests to the attacker‑controlled host or loading attacker‑controlled validation caches (tests/known‑*.json). While the request cannot set arbitrary metadata‑service headers or return response bodies, the attacker can substitute the known data files, effectively bypassing slug, module, and rack uniqueness validation. This allows an attacker to inject device definitions that would normally be rejected, compromising the integrity of the NetBox data store. No arbitrary code execution or other privilege escalation follows from this path, but the integrity of the configuration data is directly subverted.

Affected Systems

The affected product is the NetBox Device Type Library maintained by netbox‑community. The vulnerability exists in all repository revisions that predate commit 8980c690097e92f5028c7e6df402b327d827ecd5, where the NETBOX_DT_LIBRARY_URL constant can be altered by any contributor. The patch commit 8980c690 updates the constant handling to prevent this type of manipulation. Therefore any checkout of the library that has not incorporated the patch is vulnerable.

Risk and Exploitability

The CVSS score of 5.3 indicates medium severity. The EPSS score is listed as < 1%, implying a very low but non‑zero probability of exploitation. The vulnerability is not catalogued in CISA’s Known Exploited Vulnerabilities list. Based on the description, it is inferred that the attacker must submit a pull request or otherwise control the CI environment to set NETBOX_DT_LIBRARY_URL; the exploit then occurs automatically during pytest collection. Because the request cannot modify headers or response content, the risk is limited to data integrity and the bypassing of uniqueness checks rather than direct remote code execution.

Generated by OpenCVE AI on September 19, 2026 at 02:19 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the NetBox Device Type Library to a revision that includes commit 8980c690 or later, which removes the ability to alter NETBOX_DT_LIBRARY_URL in tests.
  • In CI pipelines, enforce that test configurations cannot be modified by untrusted contributors and that upstream clone URLs are validated against a whitelist.
  • Configure the test harness to reject or isolate any externally supplied known‑*.json validation caches, ensuring only trusted data files are used during collection.

Generated by OpenCVE AI on September 19, 2026 at 02:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 24 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Netbox-community
Netbox-community devicetype-library
Vendors & Products Netbox-community
Netbox-community devicetype-library

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Description NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox. In the affected repository revisions, NETBOX_DT_LIBRARY_URL in tests/test_configuration.py is a free-form tracked constant that an unauthenticated pull-request author can change before the validation test harness runs. During pytest collection, tests/definitions_test.py passes the value to Repo.clone_from and create_remote("upstream").fetch(), causing blind Git smart-HTTP requests to an attacker-selected host or loading attacker-controlled tests/known-*.json validation caches. The blind request cannot set arbitrary metadata-service headers or return response bodies, and this path does not execute remote Git hooks, but substituted known data can bypass slug, module, and rack uniqueness validation. This vulnerability is fixed in commit 8980c690097e92f5028c7e6df402b327d827ecd5.
Title NetBox Device Type Library: PR-controllable upstream clone URL (NETBOX_DT_LIBRARY_URL) enables SSRF and test-data substitution from CI
Weaknesses CWE-15
CWE-829
CWE-918
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Netbox-community Devicetype-library
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-24T20:55:23.117Z

Reserved: 2026-06-16T13:49:33.557Z

Link: CVE-2026-54918

cve-icon Vulnrichment

Updated: 2026-09-24T20:50:11.467Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T21:17:17.930

Modified: 2026-09-30T17:32:07.107

Link: CVE-2026-54918

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T02:30:17Z

Weaknesses
  • CWE-15

    External Control of System or Configuration Setting

  • CWE-829

    Inclusion of Functionality from Untrusted Control Sphere

  • CWE-918

    Server-Side Request Forgery (SSRF)