Executive brief
NetBox, a popular open-source platform for managing network infrastructure and IP addresses, contains a security flaw that allows certain authenticated users to execute unauthorized commands on the server. Users with permissions to manage export or configuration templates can bypass security restrictions by injecting malicious Python code into template settings. This could allow an attacker to take full control of the NetBox service, potentially leading to the theft of sensitive network data or disruption of operations.
Technical details
A remote code execution (RCE) vulnerability exists in NetBox's RenderTemplateMixin due to the insecure use of Django's import_string() function. The application allows users to provide an environment_params JSON field for Jinja2 templates, which includes a 'finalize' parameter resolved via import_string() without an allowlist. An authenticated attacker with 'exporttemplate' or 'configtemplate' permissions can set 'finalize' to a dangerous Python callable, such as 'subprocess.getoutput'. Because the 'finalize' callback is invoked by the Jinja2 environment internals outside of the SandboxedEnvironment's call interception mechanism, it effectively bypasses the sandbox. This allows the attacker to execute arbitrary shell commands as the NetBox service user. The issue is addressed in version 4.6.1 by implementing a strict allowlist for environment parameters.
Affected products
- NetBox Labs NetBox 4.3.5 - 4.5.4
Timeline
- 2026-04-30: disclosed: Vulnerability details published by researcher Chocapikk
- 2026-05-04: advisory: CVE-2026-29514 published
- 2026-05-14: patched: Fix committed to NetBox repository
- 2026-05-21: other: NetBox v4.6.1 released with fix
References
- https://chocapikk.com/posts/2026/netbox-export-template-rce/
- https://github.com/netbox-community/netbox/commit/d124c5fe86e12aad61285133c0caf16adcda8f2e
- https://github.com/netbox-community/netbox/issues/22079
- https://github.com/netbox-community/netbox/pull/22078
- https://github.com/netbox-community/netbox/pull/22170
- https://github.com/netbox-community/netbox/releases/tag/v4.6.1
- https://www.vulncheck.com/advisories/netbox-rce-via-rendertemplatemixin