Incomplete List of Disallowed Inputs in Nautobot - #VU151444

 

Incomplete List of Disallowed Inputs in Nautobot - #VU151444

Published: September 19, 2026


Vulnerability identifier: #VU151444
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-184
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to read arbitrary database data, modify certain database objects, and potentially gain full control of the installation.

The vulnerability exists due to an incomplete deny list in the Jinja2 template sandbox when rendering user-authored templates. A remote user can author a crafted template to read arbitrary database data, modify certain database objects, and potentially gain full control of the installation.

No user interaction or unusual template context is required.


Affected software

Nautobot

Remediation

Install security update from vendor's website.

Nautobot - addressed in versions 2.4.42, 3.2.5

External References

Related Security Bulletins