Incomplete List of Disallowed Inputs in Nautobot - #VU151444
Published: September 19, 2026
Vulnerability details
The vulnerability allows a remote user to read arbitrary database data, modify certain database objects, and potentially gain full control of the installation.
The vulnerability exists due to an incomplete deny list in the Jinja2 template sandbox when rendering user-authored templates. A remote user can author a crafted template to read arbitrary database data, modify certain database objects, and potentially gain full control of the installation.
No user interaction or unusual template context is required.