CVE-2026-55251: CWE-94: Improper Control of Generation of Code ('Code Injection') in netbox-community devicetype-library
CVE-2026-55251 is a code injection vulnerability in the netbox-community devicetype-library. The issue arises because the continuous integration (CI) workflow executes code from pull requests before any maintainer review, allowing a contributor without special repository access to run arbitrary code via modifications to certain configuration files. This vulnerability has been patched in commit f41fc1e.
AI Analysis
Technical Summary
The netbox-community devicetype-library's CI workflow (.github/workflows/validation.yml) previously ran code from pull requests before maintainer review. Specifically, three files editable by contributors—"requirements.txt", ".pre-commit-hooks-config.yaml" / ".pre-commit-yamlfmt-config.yaml", and ".gitmodules"—could be modified to execute arbitrary code on the CI runner. This improper control of code generation (CWE-94) allowed code injection by unprivileged contributors. The vulnerability was addressed by commit f41fc1e, which prevents execution of unreviewed code in the CI process.
Potential Impact
An attacker with no special repository access could execute arbitrary code on the CI runner by submitting a pull request that modifies specific configuration files. This could lead to unauthorized code execution within the CI environment, potentially compromising the build infrastructure or leaking sensitive information. The CVSS score of 6.5 indicates a medium severity with low attack complexity and no privileges required.
Mitigation Recommendations
This vulnerability has been patched by commit f41fc1e, which modifies the CI workflow to prevent execution of code from unreviewed pull requests. Users should update to include this commit or later to mitigate the issue. No additional mitigation steps are required if the patch is applied.
CVE-2026-55251: CWE-94: Improper Control of Generation of Code ('Code Injection') in netbox-community devicetype-library
Description
CVE-2026-55251 is a code injection vulnerability in the netbox-community devicetype-library. The issue arises because the continuous integration (CI) workflow executes code from pull requests before any maintainer review, allowing a contributor without special repository access to run arbitrary code via modifications to certain configuration files. This vulnerability has been patched in commit f41fc1e.
CVSS v3.1
Score 6.5medium
Affected software
netbox-community
devicetype-library
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The netbox-community devicetype-library's CI workflow (.github/workflows/validation.yml) previously ran code from pull requests before maintainer review. Specifically, three files editable by contributors—"requirements.txt", ".pre-commit-hooks-config.yaml" / ".pre-commit-yamlfmt-config.yaml", and ".gitmodules"—could be modified to execute arbitrary code on the CI runner. This improper control of code generation (CWE-94) allowed code injection by unprivileged contributors. The vulnerability was addressed by commit f41fc1e, which prevents execution of unreviewed code in the CI process.
Potential Impact
An attacker with no special repository access could execute arbitrary code on the CI runner by submitting a pull request that modifies specific configuration files. This could lead to unauthorized code execution within the CI environment, potentially compromising the build infrastructure or leaking sensitive information. The CVSS score of 6.5 indicates a medium severity with low attack complexity and no privileges required.
Mitigation Recommendations
This vulnerability has been patched by commit f41fc1e, which modifies the CI workflow to prevent execution of code from unreviewed pull requests. Users should update to include this commit or later to mitigate the issue. No additional mitigation steps are required if the patch is applied.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-06-16T16:44:00.625Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6abebc2da43b0b3b89f67a39
Added to database: 10/01/2026, 20:01:49 UTC
Last enriched: 10/01/2026, 20:17:23 UTC
Last updated: 10/02/2026, 03:51:34 UTC
Views: 11
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.