Executive brief
NetBox is an open-source platform used to manage and track network infrastructure and IP addresses. When a user attempts to delete an object that has protected relationships, the system displays an error message. A vulnerability in this error handling allows attackers who can control object names to inject malicious code that executes in the browser of privileged users viewing the error, potentially leading to account hijacking or unauthorized actions within the platform.
Technical details
This is a reflected cross-site scripting (XSS) vulnerability in NetBox's ProtectedError exception handler (utilities/error_handlers.py). When a delete operation fails due to protected relationships, object display names are inserted into HTML error messages without proper HTML escaping, allowing user-controlled content to be rendered directly in the web interface. The vulnerability affects NetBox versions 2.11.0 through 3.7.x. An attacker with the ability to set or control object names can craft payloads that execute arbitrary JavaScript in the context of a privileged user's browser session, potentially enabling session hijacking, privilege escalation, or unauthorized administrative actions. This is a reflected XSS, so the payload must be triggered via a specific request (a failed delete operation), but no special authentication or privileges are necessarily required to create objects with malicious names.
Affected products
- NetBox Community NetBox 2.11.0 through 3.7.x
Timeline
- 2026-02-03: disclosed