Impact
The vulnerability allows an unauthenticated contributor to inject arbitrary code into the continuous integration (CI) workflow by editing pull‑request–editable files such as requirements.txt, .pre-commit‑hooks‑config.yaml, and .gitmodules. When the NetBox Device Type Library CI pipeline runs, it executes code contained in those files before any maintainer review. An attacker can therefore run malicious scripts on the CI runner, potentially compromising the integrity of the library repository and any downstream deployments that import the device types. The weakness is identified by CWE-494, CWE-829, and CWE-94, indicating executable code injection and permission misuse.
Affected Systems
The affected product is the NetBox Device Type Library maintained by netbox‑community. Any release of the library before the patch commit f41fc1e48dec8d7d31afba5f13a8c73652ff5796 is vulnerable. The repository hosts pull‑request workflows that are publicly editable, making the issue suitable for anyone with PR permissions.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity. EPSS for this vulnerability is not available, and it is not listed in the CISA KEV catalog, suggesting no public exploitation data yet. However, the attack vector is inferred to be a public pull request that modifies the workflow configuration; thus the vulnerability is exploitable by anyone able to open a PR. Exploitation would lead to arbitrary code execution in the CI environment and could compromise the integrity of the device type library and subsequent imports into NetBox.
OpenCVE Enrichment