PT-2026-97022 · Nautobot · Nautobot

CVE-2026-83801

·

Published

2026-09-22

·

Updated

2026-09-22

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Nautobot versions prior to 2.4.37 Nautobot versions prior to 3.1.8
Description Users with specific permissions can store HTML or JavaScript in a Relationship description or a Module Family name. Nautobot assigns these values to form field help text rendered by render field.html through Django's |safe filter without adequate neutralization, bypassing auto-escaping. The stored content executes in the authenticated browser session of any user, including administrators or superusers, who opens an affected create or edit form. This can enable actions as the victim, session or token theft, and further privilege escalation.
Recommendations Update to version 2.4.37 or newer. Update to version 3.1.8 or newer. Restrict extras.add relationship, extras.change relationship, dcim.add modulefamily, and dcim.change modulefamily permissions to fully trusted administrators only. Audit existing Relationship description values and Module Family name values for embedded HTML or <script> content and remove any payloads.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-83801
GHSA-56V6-2FHR-WXGQ

Affected Products

Nautobot