Impact
The vulnerability arises from a free‑form constant, NETBOX_DT_LIBRARY_URL, that can be modified by an unauthenticated pull‑request author before the test harness runs. During pytest collection the value is passed to Repo.clone_from and create_remote('upstream').fetch(), forcing blind Git smart‑HTTP requests to the attacker‑controlled host or loading attacker‑controlled validation caches (tests/known‑*.json). While the request cannot set arbitrary metadata‑service headers or return response bodies, the attacker can substitute the known data files, effectively bypassing slug, module, and rack uniqueness validation. This allows an attacker to inject device definitions that would normally be rejected, compromising the integrity of the NetBox data store. No arbitrary code execution or other privilege escalation follows from this path, but the integrity of the configuration data is directly subverted.
Affected Systems
The affected product is the NetBox Device Type Library maintained by netbox‑community. The vulnerability exists in all repository revisions that predate commit 8980c690097e92f5028c7e6df402b327d827ecd5, where the NETBOX_DT_LIBRARY_URL constant can be altered by any contributor. The patch commit 8980c690 updates the constant handling to prevent this type of manipulation. Therefore any checkout of the library that has not incorporated the patch is vulnerable.
Risk and Exploitability
The CVSS score of 5.3 indicates medium severity. The EPSS score is listed as < 1%, implying a very low but non‑zero probability of exploitation. The vulnerability is not catalogued in CISA’s Known Exploited Vulnerabilities list. Based on the description, it is inferred that the attacker must submit a pull request or otherwise control the CI environment to set NETBOX_DT_LIBRARY_URL; the exploit then occurs automatically during pytest collection. Because the request cannot modify headers or response content, the risk is limited to data integrity and the bypassing of uniqueness checks rather than direct remote code execution.
OpenCVE Enrichment