Sceawere

Vulnerability Detail

CVE-2026-104073UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

NetBox Server-Side Template Injection

Vulnerability Metadata

Severity
High
Score / CVSS
7.6
Creation Date
6h ago
Vendor
netbox-community
Product
netbox
Attack Type
Exposure of Resource to Wrong Sphere
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

NetBox versions 2.9.5 before 4.7.0 contain a server-side template injection vulnerability that allows a low-privileged user with the "Can add custom links" permission to steal session cookies and API tokens of other users by exposing the raw Django HttpRequest object to the Jinja2 template context. Attackers can craft a custom link template embedding request.COOKIES['sessionid'] or a user's API token into an img src URL, which bypasses the clean_html sanitizer and auto-exfiltrates the victim's credentials to an attacker-controlled host when a privileged user views the object, enabling full account takeover.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.6",
  "pubDate": "2026-10-06T19:17:40.143Z",
  "pubdate": "2026-10-06T19:17:40.143Z",
  "executiveSummary": "NetBox versions 2.9.5 through 4.7.0 are susceptible to a critical server-side template injection (SSTI) vulnerability. The flaw originates from the improper exposure of the Django HttpRequest object within the Jinja2 template rendering context.\nA low-privileged user possessing the 'Can add custom links' permission can weaponize this access to perform cross-site scripting (XSS) and unauthorized data exfiltration. By embedding malicious Jinja2 syntax into custom link fields, an attacker can extract sensitive information, such as session cookies and API tokens, from other users, including administrators.\nThe vulnerability bypasses the clean_html sanitizer, facilitating the automated transmission of hijacked credentials to an attacker-controlled endpoint. This allows for full account takeover and subsequent compromise of the NetBox instance, posing a significant risk to the integrity and confidentiality of network documentation managed within the platform.",
  "technicalDetails": "The root cause of this vulnerability is the insecure inclusion of the raw Django HttpRequest object in the template context during the rendering of custom links. Jinja2, the template engine utilized by NetBox, evaluates expressions within the template context; by exposing the request object, the application grants templates access to sensitive attributes, including cookie data and header information.\nAn attacker with 'Can add custom links' permissions can exploit this by injecting malicious Jinja2 template syntax into the URL field of a custom link object. Because the application processes these templates server-side before rendering, the malicious code is executed whenever the page containing the custom link is viewed by another user.\nThe exploitation flow proceeds as follows: First, the attacker crafts a payload utilizing the request object, such as {{ request.COOKIES['sessionid'] }} or access tokens, embedded within the src attribute of an HTML img tag. Second, this payload is saved within the custom link configuration. Third, when a target user—typically one with higher privileges—views the affected object, the server renders the template, substituting the attacker's placeholders with the victim's live session identifiers or API keys.\nThe resulting rendered HTML forces the victim's browser to initiate a request to an attacker-controlled external host. The sensitive data is appended to this outgoing request via URL parameters, effectively bypassing the clean_html security sanitizer which fails to inspect or block the server-side generated content before it reaches the client's browser.\nThis execution path provides the attacker with reliable, automated exfiltration of authentication material. Upon successful exfiltration, the attacker can leverage the stolen sessionid or API token to impersonate the victim, leading to full account takeover. Given the nature of NetBox, this escalation often results in administrative control over the entire network infrastructure documentation, allowing for unauthorized modifications, data theft, or further lateral movement within the environment. This vulnerability is particularly dangerous because it does not require external network exposure of the template engine itself, as the exploitation is triggered via the legitimate application interface."
}
CVE-2026-104073: NetBox Server-Side Template Injection (HIGH Severity, CVSS: 7.6) | Sceawere