External risk intelligence

NetBox Device Type Library Pickle Deserialization Code Execution

CVE advisorySeverity: CRITICAL (CVSS 9.6)

CVE-2026-54752

The vulnerability exists within a test harness and configuration files used for processing pull requests in a development repository. It is a build-time or developer-centric process involving local test execution and CI/CD pipelines, not a public-facing service, network application, or production-deployed appliance.

Deserialization

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability in the NetBox Device Type Library's testing process could allow for arbitrary code execution when processing community-submitted definitions. This could impact the integrity and availability of resources within the development or testing environments where these tests are run. The main concern at this time is confirming relevance and exposure.

  • A flaw exists in how community device definitions are tested.
  • It risks code execution in development and testing systems.
  • Confirm this issue does not affect your systems.

Attack Path

How an attacker could exploit the issue

An unauthenticated contributor could manipulate configuration settings and supply specially crafted pickle files. When these files are loaded by the test harness during a test run, the deserialization process allows for arbitrary code execution. This could occur within the GitHub Actions runner or on a maintainer's system, potentially compromising sensitive resources.

  • No authentication required.
  • Loading crafted pickle files during tests.
  • Arbitrary code execution.

Live Threat

Current exploitation, exposure, and threat context

When the NetBox Device Type Library's test harness is triggered, specifically during pull request validation, an unauthenticated contributor could craft malicious pickle cache files. If these files are loaded by the test suite, they could lead to arbitrary code execution on the runner, potentially impacting the confidentiality, integrity, and availability of connected resources.

  • Code execution on test runners.
  • Loading specially crafted pickle files.
  • Compromise of development and CI/CD systems.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability impacts the NetBox Device Type Library's test harness, potentially affecting development environments and CI/CD pipelines. Action is required by teams managing the NetBox development process, including application owners and security teams overseeing code repositories and build systems. The first step is to identify if the affected test code is being executed in any environment, confirm its reachability and criticality, and then plan remediation with the vendor or development team.

  • NetBox development and security teams own the issue.
  • Verify test execution in development and CI/CD.
  • Coordinate fix with the development team.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the NetBox Device Type Library?

The NetBox Device Type Library is a community-sourced collection of hardware specifications used to populate device templates in NetBox. Engineers rely on these definitions to model their network infrastructure, such as switch or server models, to ensure their NetBox instances correctly represent their physical environment.

How does this CVE-2026-54752 vulnerability work?

This issue involves Deserialization of Untrusted Data (CWE-502). The software uses Python's pickle module to load configuration files during testing. Because pickle can be instructed to execute arbitrary commands, an attacker providing a malicious file can trigger unintended code execution when the test suite runs.

What triggers this security flaw?

The vulnerability is triggered only when the test harness processes a crafted pickle file during a test execution. It does not occur during standard operation of a NetBox instance. Simply using the library's device definitions in production does not activate the bug; it requires running the library's internal validation tests.

Is this vulnerability a risk for my production systems?

According to Halo Surface Signal, this is very unlikely. The flaw is confined to build-time or developer-centric processes—specifically CI/CD pipelines or local testing environments—rather than a production-deployed application. It primarily impacts maintainers and systems that execute the library's test suite.

What should I do if I manage this software?

If you maintain development or CI/CD pipelines that execute these tests, verify if your current environment runs the affected test harness. Ensure you are utilizing the updated code provided by the maintainers to close this deserialization path and secure your development infrastructure against potential code execution.

References