CVE-2026-55251: NetBox Device Type Library: Arbitrary Code Execution on CI Runner Through Malicious requirements.txt, .pre-commit-hooks-config.yaml, and .gitmodules Files
NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox. Prior to commit f41fc1e, the CI workflow .github/workflows/validation.yml runs on pullrequest and executes code supplied by the pull request before any maintainer review. Three PR-editable files drive this: "requirements.txt", ".pre-commit-hooks-config.yaml" / ".pre-commit-yamlfmt-config.yaml", and ".gitmodules". A contributor with no special repository access could open a pull request that modifies these files and have their code run on the CI runner. This issue has been patched via commit f41fc1e.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
NetBox Device Type Libraryto a version that resolves this vulnerability.Patch f41fc1e
Event History
Frequently Asked Questions
Who can exploit this issue?
Any contributor able to open a pull request could exploit it; no special repository permissions or maintainer review were required on affected CI workflows.
What conditions are required for exploitation?
The affected validation workflow must run for pull requests and execute PR-controlled content. An attacker can modify requirements.txt, .pre-commit-hooks-config.yaml, .pre-commit-yamlfmt-config.yaml, or .gitmodules to cause code execution on the CI runner.
How can I determine whether the issue is fixed?
Check whether the repository includes commit f41fc1e. Versions or repository states prior to that commit are affected.
What can be done if the patch cannot be applied immediately?
The provided information identifies the vulnerable path as the pull-request validation workflow executing content from PR-editable dependency, pre-commit, and submodule configuration files. Restricting or avoiding execution of those PR-controlled files in the workflow would address that exposure, but no specific interim mitigation is provided.