Cleartext storage of sensitive information in Nautobot - #VU151443

 

Cleartext storage of sensitive information in Nautobot - #VU151443

Published: September 19, 2026


Vulnerability identifier: #VU151443
CSH Severity: Medium
CVSS v4: 8.5 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-312
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose API tokens and password hashes and gain administrative control of the Nautobot instance.

The vulnerability exists due to cleartext storage of sensitive information in Custom Link Jinja2 template rendering when rendering a custom link on an object detail page. A remote user can create a crafted Custom Link that exfiltrates credentials when viewed to disclose API tokens and password hashes and gain administrative control of the Nautobot instance.

User interaction is required because a viewer must follow the crafted link.


Affected software

Nautobot

Remediation

Install security update from vendor's website.

Nautobot - addressed in versions 2.4.42, 3.2.5

External References

Related Security Bulletins