PT-2026-95095 · Unknown · Netbox Device Type Library

·

CVE-2026-54752

·

Published

2026-09-17

·

Updated

2026-09-17

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions NetBox Device Type Library (affected versions not specified)
Description The validation test harness allows the deserialization of tracked pickle cache files via the pickle.load method within the read pickle data() function located in tests/pickle operations.py. An unauthenticated contributor can modify USE LOCAL KNOWN SLUGS in tests/test configuration.py and provide a malicious tests/known-modules.pickle or tests/known-racks.pickle file. When pytest is executed, tests/definitions test.py loads these files, triggering attacker-controlled object reduction behavior. This leads to arbitrary code execution within the GitHub Actions runner or a maintainer's process running the tests, compromising the confidentiality, integrity, and availability of accessible resources.
Recommendations Apply the fix provided in commit 1c6f7e2b93589b965318c6e67ac3504831f0e71e.

Exploit

Fix

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-54752
GHSA-492P-5WP7-2W7C

Affected Products

Netbox Device Type Library