PT-2026-97022 · Nautobot · Nautobot
CVE-2026-83801
·
Published
2026-09-22
·
Updated
2026-09-22
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Nautobot versions prior to 2.4.37
Nautobot versions prior to 3.1.8
Description
Users with specific permissions can store HTML or JavaScript in a Relationship description or a Module Family name. Nautobot assigns these values to form field
help text rendered by render field.html through Django's |safe filter without adequate neutralization, bypassing auto-escaping. The stored content executes in the authenticated browser session of any user, including administrators or superusers, who opens an affected create or edit form. This can enable actions as the victim, session or token theft, and further privilege escalation.Recommendations
Update to version 2.4.37 or newer.
Update to version 3.1.8 or newer.
Restrict
extras.add relationship, extras.change relationship, dcim.add modulefamily, and dcim.change modulefamily permissions to fully trusted administrators only.
Audit existing Relationship description values and Module Family name values for embedded HTML or <script> content and remove any payloads.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nautobot