CVE-2026-55251
Received Received - Intake

CI Workflow Code Execution in NetBox Device Type Library

Vulnerability report for CVE-2026-55251, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: GitHub, Inc.

Description

NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox. Prior to commit f41fc1e, the CI workflow .github/workflows/validation.yml runs on pull_request and executes code supplied by the pull request before any maintainer review. Three PR-editable files drive this: "requirements.txt", ".pre-commit-hooks-config.yaml" / ".pre-commit-yamlfmt-config.yaml", and ".gitmodules". A contributor with no special repository access could open a pull request that modifies these files and have their code run on the CI runner. This issue has been patched via commit f41fc1e.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-02
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
netbox_community devicetype_library *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-829 The product imports, requires, or includes executable functionality (such as a library) from a source that is outside of the intended control sphere.
CWE-494 The product downloads source code or an executable from a remote location and executes the code without sufficiently verifying the origin and integrity of the code.
CWE-94 The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-55251 is a security flaw in the NetBox Device Type Library repository where the CI workflow executes untrusted code from pull requests. Three editable files (requirements.txt, pre-commit configs, and .gitmodules) allow contributors to inject malicious code before maintainer review. The CI workflow runs on pull_request events, enabling arbitrary code execution during CI execution.

Detection Guidance

This vulnerability is specific to the NetBox Device Type Library CI workflow and cannot be directly detected on general networks or systems. Check if your repository uses similar CI workflows with editable files like requirements.txt or .gitmodules. Review GitHub Actions logs for suspicious PR executions or unauthorized file modifications.

Impact Analysis

An attacker could modify CI control files to execute malicious code during CI runs. This could lead to stealing cloud metadata credentials from the temporary GitHub runner environment. While the impact is limited to the runner due to a read-only token, credential theft could enable further attacks if cloud credentials are compromised.

Compliance Impact

This vulnerability primarily affects supply chain security and CI/CD pipeline integrity rather than direct data exposure. It could indirectly impact compliance by enabling attackers to steal cloud metadata credentials during CI execution, which might lead to unauthorized access to regulated data if cloud resources are compromised. However, the vulnerability itself does not directly violate GDPR or HIPAA unless credentials are used to access protected data.

Mitigation Strategies

Apply the patch from commit f41fc1e to harden CI workflows. Restrict file modifications to approved directories for non-maintainers. Implement permission-based checks and require a ci-approved label for PRs. Pin dependency hashes in requirements files and validate input paths using git diff checks.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-55251. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart