PatchSiren

netbox-community CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL netbox-community CVE published 2026-09-17

CVE-2026-54752

CVE-2026-54752 is a critical vulnerability in the NetBox Device Type Library that allows for arbitrary code execution due to insecure deserialization of pickle cache files. An unauthenticated contributor can exploit this by supplying a crafted pickle file that, when loaded during testing, invokes attacker-controlled object reduction behavior. This vulnerability has been fixed with commit 1c6f7e2b93589b965 [truncated]

HIGH netbox-community CVE published 2026-05-04

CVE-2026-29514

A remote code execution vulnerability exists in NetBox versions 4.3.5 through 4.5.4. The RenderTemplateMixin.get_environment_params() method allows authenticated users with exporttemplate or configtemplate permissions to execute arbitrary code by specifying malicious Python callables in the environment_params field. Attackers can bypass Jinja2 SandboxedEnvironment protections by setting the finalize param [truncated]