Description
NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox. Prior to commit f41fc1e, the CI workflow .github/workflows/validation.yml runs on pull_request and executes code supplied by the pull request before any maintainer review. Three PR-editable files drive this: "requirements.txt", ".pre-commit-hooks-config.yaml" / ".pre-commit-yamlfmt-config.yaml", and ".gitmodules". A contributor with no special repository access could open a pull request that modifies these files and have their code run on the CI runner. This issue has been patched via commit f41fc1e.
Published: 2026-10-01
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability allows an unauthenticated contributor to inject arbitrary code into the continuous integration (CI) workflow by editing pull‑request–editable files such as requirements.txt, .pre-commit‑hooks‑config.yaml, and .gitmodules. When the NetBox Device Type Library CI pipeline runs, it executes code contained in those files before any maintainer review. An attacker can therefore run malicious scripts on the CI runner, potentially compromising the integrity of the library repository and any downstream deployments that import the device types. The weakness is identified by CWE-494, CWE-829, and CWE-94, indicating executable code injection and permission misuse.

Affected Systems

The affected product is the NetBox Device Type Library maintained by netbox‑community. Any release of the library before the patch commit f41fc1e48dec8d7d31afba5f13a8c73652ff5796 is vulnerable. The repository hosts pull‑request workflows that are publicly editable, making the issue suitable for anyone with PR permissions.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate severity. EPSS for this vulnerability is not available, and it is not listed in the CISA KEV catalog, suggesting no public exploitation data yet. However, the attack vector is inferred to be a public pull request that modifies the workflow configuration; thus the vulnerability is exploitable by anyone able to open a PR. Exploitation would lead to arbitrary code execution in the CI environment and could compromise the integrity of the device type library and subsequent imports into NetBox.

Generated by OpenCVE AI on October 1, 2026 at 21:54 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the NetBox Device Type Library to the patched commit f41fc1e48dec8d7d31afba5f13a8c73652ff5796 or later.
  • Modify the repository settings to restrict modifications to CI workflow files to maintainers or protected branches, preventing pull requests from altering .github/workflows/validation.yml and related configuration files.
  • Configure GitHub Actions to run with the least privilege and enforce approvals before executing code from PR‑editable files, ensuring that only trusted code runs on the CI runner.

Generated by OpenCVE AI on October 1, 2026 at 21:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 22:00:00 +0000

Type Values Removed Values Added
First Time appeared Netbox-community
Netbox-community devicetype-library
Vendors & Products Netbox-community
Netbox-community devicetype-library

Thu, 01 Oct 2026 20:00:00 +0000

Type Values Removed Values Added
Description NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox. Prior to commit f41fc1e, the CI workflow .github/workflows/validation.yml runs on pull_request and executes code supplied by the pull request before any maintainer review. Three PR-editable files drive this: "requirements.txt", ".pre-commit-hooks-config.yaml" / ".pre-commit-yamlfmt-config.yaml", and ".gitmodules". A contributor with no special repository access could open a pull request that modifies these files and have their code run on the CI runner. This issue has been patched via commit f41fc1e.
Title NetBox Device Type Library: Arbitrary Code Execution on CI Runner Through Malicious requirements.txt, .pre-commit-hooks-config.yaml, and .gitmodules Files
Weaknesses CWE-494
CWE-829
CWE-94
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}


Subscriptions

Netbox-community Devicetype-library
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-01T19:49:32.741Z

Reserved: 2026-06-16T16:44:00.625Z

Link: CVE-2026-55251

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-01T20:17:25.957

Modified: 2026-10-01T20:17:25.957

Link: CVE-2026-55251

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T22:00:17Z

Weaknesses
  • CWE-494

    Download of Code Without Integrity Check

  • CWE-829

    Inclusion of Functionality from Untrusted Control Sphere

  • CWE-94

    Improper Control of Generation of Code ('Code Injection')