CVE-2026-55251: NetBox Device Type Library: Arbitrary Code Execution on CI Runner Through Malicious requirements.txt, .pre-commit-hooks-config.yaml, and .gitmodules Files

Published Oct 1, 2026
·
Updated

NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox. Prior to commit f41fc1e, the CI workflow .github/workflows/validation.yml runs on pullrequest and executes code supplied by the pull request before any maintainer review. Three PR-editable files drive this: "requirements.txt", ".pre-commit-hooks-config.yaml" / ".pre-commit-yamlfmt-config.yaml", and ".gitmodules". A contributor with no special repository access could open a pull request that modifies these files and have their code run on the CI runner. This issue has been patched via commit f41fc1e.

Affected Software

1 affected component
NetBox Device Type Library

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade NetBox Device Type Library to a version that resolves this vulnerability.

    Patch f41fc1e

Event History

Oct 1, 2026
CVE Published
via MITRE·07:49 PM
Data Sourced
via MITRE·07:49 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

Any contributor able to open a pull request could exploit it; no special repository permissions or maintainer review were required on affected CI workflows.

2

What conditions are required for exploitation?

The affected validation workflow must run for pull requests and execute PR-controlled content. An attacker can modify requirements.txt, .pre-commit-hooks-config.yaml, .pre-commit-yamlfmt-config.yaml, or .gitmodules to cause code execution on the CI runner.

3

How can I determine whether the issue is fixed?

Check whether the repository includes commit f41fc1e. Versions or repository states prior to that commit are affected.

4

What can be done if the patch cannot be applied immediately?

The provided information identifies the vulnerable path as the pull-request validation workflow executing content from PR-editable dependency, pre-commit, and submodule configuration files. Restricting or avoiding execution of those PR-controlled files in the workflow would address that exposure, but no specific interim mitigation is provided.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203