Unauthenticated db-file-storage views
Modified: 11/22/2024
package
pkg:pypi/nautobot
Unauthenticated db-file-storage views
Modified: 11/22/2024
Nautobot vulnerable to remote code execution via Jinja2 template rendering
Modified: 9/25/2024
Nautobot: Webhook definitions could be used for server-side request forgery (SSRF)
Modified: 5/13/2026
Cross-site Scripting potential in custom links, job buttons, and computed fields
Modified: 11/22/2024
nautobot has reflected Cross-site Scripting potential in all object list views
Modified: 5/1/2024
Unauthenticated views may expose information to anonymous users
Modified: 3/26/2024
Nautobot: GitRepository.current_head field should not be writable through REST API
Modified: 5/13/2026
Nautobot dynamic-group-members doesn't enforce permission restrictions on member objects
Modified: 2/4/2026
Nautobot: Object bulk rename UI actions vulnerable to denial of service by crafted regular expression (REDoS)
Modified: 5/13/2026
Nautobot's BANNER_* configuration can be used to inject arbitrary HTML content into Nautobot pages
Modified: 5/19/2024
Nautobot vulnerable to exposure of hashed user passwords via REST API
Modified: 10/7/2024
Nautobot may allows uploaded media files to be accessible without authentication
Modified: 6/10/2025
XSS potential in rendered Markdown fields (comments, description, notes, etc.)
Modified: 2/15/2025
Nautobot missing object-level permissions enforcement when running Job Buttons
Modified: 11/22/2024
Nautobot vulnerable to secrets exposure and data manipulation through Jinja2 templating
Modified: 5/19/2026
Nautobot: REST API permits creation of GenericForeignKey references to objects that the user should not be able to reference
Modified: 5/13/2026
Nautobot: Management of users via REST API does not apply configured password validators
Modified: 3/31/2026
Modified: 11/8/2023
Modified: 11/21/2024
Modified: 6/8/2026
Modified: 6/8/2026
Modified: 11/8/2023
Modified: 1/29/2024
Modified: 2/4/2026
Modified: 5/21/2026