PT-2026-95095 · Unknown · Netbox Device Type Library
CVSS v3.1
9.6
Critical
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
NetBox Device Type Library (affected versions not specified)
Description
The validation test harness allows the deserialization of tracked pickle cache files via the
pickle.load method within the read pickle data() function located in tests/pickle operations.py. An unauthenticated contributor can modify USE LOCAL KNOWN SLUGS in tests/test configuration.py and provide a malicious tests/known-modules.pickle or tests/known-racks.pickle file. When pytest is executed, tests/definitions test.py loads these files, triggering attacker-controlled object reduction behavior. This leads to arbitrary code execution within the GitHub Actions runner or a maintainer's process running the tests, compromising the confidentiality, integrity, and availability of accessible resources.Recommendations
Apply the fix provided in commit 1c6f7e2b93589b965318c6e67ac3504831f0e71e.
Exploit
Fix
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Netbox Device Type Library