以下是该漏洞描述的中文翻译: NetBox Device Type Library 是一个社区贡献的设备类型定义集合,用于导入 NetBox。在受影响的代码仓库版本中, 中的 是一个自由格式的受控常量,未认证的 Pull Request 提交者可以在验证测试框架运行前对其进行修改。 在 pytest 收集阶段, 会将该值传递给 和 ,从而导致向攻击者选定的主机发起盲式 Git 智能 HTTP 请求,或加载攻击者可控的 验证缓存。 该盲式请求无法设置任意的元数据服务请求头或返回响应体,且此路径不会执行远程 Git 钩
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| netbox-community | devicetype-library | < 8980c690097e92f5028c7e6df402b327d827ecd5 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-54752 | 9.6 CRITICAL | NetBox Device Type Library: Insecure Pickle Deserialization in Test Suite Allows Remote Co |
| CVE-2026-54916 | 8.8 HIGH | NetBox Device Type Library: Module Shadowing Bypass of prior pickle fix - RCE via missing |
No comments yet