๐Ÿ” CVE Alert

CVE-2026-55251

MEDIUM 6.5

NetBox Device Type Library: Arbitrary Code Execution on CI Runner Through Malicious requirements.txt, .pre-commit-hooks-config.yaml, and .gitmodules Files

CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th

NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox. Prior to commit f41fc1e, the CI workflow .github/workflows/validation.yml runs on pull_request and executes code supplied by the pull request before any maintainer review. Three PR-editable files drive this: "requirements.txt", ".pre-commit-hooks-config.yaml" / ".pre-commit-yamlfmt-config.yaml", and ".gitmodules". A contributor with no special repository access could open a pull request that modifies these files and have their code run on the CI runner. This issue has been patched via commit f41fc1e.

CWE CWE-94 CWE-494 CWE-829
Vendor netbox-community
Product devicetype-library
Published Oct 1, 2026
Stay Ahead of the Next One

Get instant alerts for netbox-community devicetype-library

Be the first to know when new medium vulnerabilities affecting netbox-community devicetype-library are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
None

Affected Versions

netbox-community / devicetype-library
< f41fc1e48dec8d7d31afba5f13a8c73652ff5796

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/netbox-community/devicetype-library/security/advisories/GHSA-5x2m-x42f-g4cm github.com: https://github.com/netbox-community/devicetype-library/commit/f41fc1e48dec8d7d31afba5f13a8c73652ff5796