NetBox Device Type Library 是一个供导入 NetBox 的社区贡献的设备类型定义集合。由于缺少 文件,且未设置 ,导致 pytest 的默认“prepend”导入模式会在测试收集阶段将 目录置于 的最前端。这使得未经验证的贡献者可以通过添加如 这样的模块来遮蔽(shadow)GitPython 库,从而在 执行 时生效;或者通过添加 实现在测试收集时自动执行代码。Python 会在任何测试函数运行之前导入并执行该模块,从而允许攻击者在 GitHub Actions 运行环境中执行任意代码、
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| netbox-community | devicetype-library | < b0d9a3dadd0a0a9d3c93b0b2777559fd4bad1037g | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-54752 | 9.6 CRITICAL | NetBox Device Type Library: Insecure Pickle Deserialization in Test Suite Allows Remote Co |
| CVE-2026-54918 | 5.3 MEDIUM | NetBox Device Type Library: PR-controllable upstream clone URL (NETBOX_DT_LIBRARY_URL) ena |
No comments yet