{"id":"GHSA-56v6-2fhr-wxgq","summary":"Nautobot: Stored cross-site scripting (XSS) in object create/edit form help text","details":"### Impact\n_What kind of vulnerability is it? Who is impacted?_\n\nIt has two related instances that share the same root cause: a user-controlled model field is assigned verbatim to a form field's `help_text`, which is rendered with Django's `|safe` filter (`render_field.html`), bypassing auto-escaping.\n\nIn both cases the script executes in the browser of any user who opens an affected create or edit form, **including administrators and superusers**. Because the payload runs in the victim's authenticated session, it can lead to actions performed as the victim, session/token theft, and further privilege escalation. Exploitation requires the victim to open an affected form.\n\n#### Relationship description\n\nA user who holds the add/change permission for Relationships (`extras.add_relationship` / `extras.change_relationship`) can set a Relationship's **description** to an HTML/JavaScript payload. That description is used as the help text of the relationship's form field and is rendered on the create/edit page of every object type the relationship applies to.\n\n#### Module Family name\n\nA user who holds the add/change permission for Module Families (`dcim.add_modulefamily` / `dcim.change_modulefamily`) can put a payload in a Module Family **name**, which is interpolated into the `module_family` field's help text on the Module \"Install module\" form for any module bay assigned to that family.\n\n### Patches\n_Has the problem been patched? What versions should users upgrade to?_\n\nFixes are available in Nautobot v2.4.37+ & v3.1.8+\n\n\u003e Note: The underlying weakness exists in earlier EOL versions of Nautobot (v1.x). Users on those older EOL versions are highly encouraged to upgrade to a supported version.\n\n### Workarounds\n_Is there a way for users to fix or remediate the vulnerability without upgrading?_\n\nThere is no configuration-only fix. To remediate without upgrading:\n\n- Restrict the `extras.add_relationship` / `extras.change_relationship` and `dcim.add_modulefamily` / `dcim.change_modulefamily` permissions to fully trusted administrators only.\n- Audit existing Relationship **description** values and Module Family **name** values for embedded HTML / `\u003cscript\u003e` content and remove any payloads.\n\nNote that limiting who can open create/edit forms does not fully mitigate the issue, since the payload targets any user (including admins) who opens an affected form.\n\n### Credit\n\nCredit for this discovery goes to Habibullo Izzatilloyev.","aliases":["CVE-2026-83801","PYSEC-2026-4110"],"modified":"2026-10-01T17:55:35.934130115Z","published":"2026-09-22T20:37:30Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-09-22T20:37:30Z","nvd_published_at":null,"cwe_ids":["CWE-79"]},"references":[{"type":"WEB","url":"https://github.com/nautobot/nautobot/security/advisories/GHSA-56v6-2fhr-wxgq"},{"type":"WEB","url":"https://github.com/nautobot/nautobot/commit/e6ff20d50e0759135c6d278e7b2ceec56ed9b3c8"},{"type":"WEB","url":"https://github.com/nautobot/nautobot/commit/f8a62466f3ebc42759a6373e7c79b0cad5751c2f"},{"type":"PACKAGE","url":"https://github.com/nautobot/nautobot"},{"type":"WEB","url":"https://github.com/nautobot/nautobot/releases/tag/v2.4.37"},{"type":"WEB","url":"https://github.com/nautobot/nautobot/releases/tag/v3.1.8"}],"affected":[{"package":{"name":"nautobot","ecosystem":"PyPI","purl":"pkg:pypi/nautobot"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.4.37"}]}],"versions":["1.0.0","1.0.0a1","1.0.0a2","1.0.0b1","1.0.0b2","1.0.0b3","1.0.0b4","1.0.1","1.0.2","1.0.3","1.1.0","1.1.1","1.1.2","1.1.3","1.1.4","1.1.5","1.1.6","1.2.0","1.2.1","1.2.10","1.2.11","1.2.2","1.2.3","1.2.4","1.2.5","1.2.6","1.2.7","1.2.8","1.2.9","1.3.0","1.3.1","1.3.10","1.3.2","1.3.3","1.3.4","1.3.5","1.3.6","1.3.7","1.3.8","1.3.9","1.4.0","1.4.1","1.4.10","1.4.2","1.4.3","1.4.4","1.4.5","1.4.7","1.4.8","1.4.9","1.5.0","1.5.1","1.5.10","1.5.11","1.5.12","1.5.13","1.5.14","1.5.15","1.5.16","1.5.17","1.5.18","1.5.19","1.5.2","1.5.20","1.5.21","1.5.22","1.5.23","1.5.24","1.5.3","1.5.4","1.5.5","1.5.6","1.5.7","1.5.8","1.5.9","1.6.0","1.6.1","1.6.10","1.6.11","1.6.12","1.6.13","1.6.14","1.6.15","1.6.16","1.6.17","1.6.18","1.6.19","1.6.2","1.6.20","1.6.21","1.6.22","1.6.23","1.6.24","1.6.25","1.6.26","1.6.27","1.6.28","1.6.29","1.6.3","1.6.30","1.6.31","1.6.32","1.6.4","1.6.5","1.6.6","1.6.7","1.6.8","1.6.9","2.0.0","2.0.1","2.0.2","2.0.3","2.0.4","2.0.5","2.0.6","2.1.0","2.1.0b1","2.1.1","2.1.2","2.1.3","2.1.4","2.1.5","2.1.6","2.1.7","2.1.8","2.1.9","2.2.0","2.2.0b1","2.2.1","2.2.2","2.2.3","2.2.4","2.2.5","2.2.6","2.2.7","2.2.8","2.2.9","2.3.0","2.3.0b1","2.3.1","2.3.10","2.3.11","2.3.12","2.3.13","2.3.14","2.3.15","2.3.15b1","2.3.16","2.3.2","2.3.3","2.3.4","2.3.5","2.3.6","2.3.7","2.3.8","2.3.9","2.4.0","2.4.0b1","2.4.1","2.4.10","2.4.11","2.4.12","2.4.13","2.4.14","2.4.15","2.4.16","2.4.17","2.4.18","2.4.19","2.4.2","2.4.20","2.4.21","2.4.22","2.4.23","2.4.24","2.4.25","2.4.26","2.4.27","2.4.28","2.4.29","2.4.3","2.4.30","2.4.31","2.4.32","2.4.33","2.4.34","2.4.35","2.4.36","2.4.4","2.4.5","2.4.6","2.4.7","2.4.8","2.4.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-56v6-2fhr-wxgq/GHSA-56v6-2fhr-wxgq.json"}},{"package":{"name":"nautobot","ecosystem":"PyPI","purl":"pkg:pypi/nautobot"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.0.0"},{"fixed":"3.1.8"}]}],"versions":["3.0.0","3.0.1","3.0.10","3.0.11","3.0.2","3.0.3","3.0.4","3.0.5","3.0.6","3.0.7","3.0.8","3.0.9","3.1.0","3.1.0a1","3.1.0a2","3.1.0a3","3.1.0a4","3.1.0a5","3.1.1","3.1.2","3.1.3","3.1.4","3.1.5","3.1.6","3.1.7"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-56v6-2fhr-wxgq/GHSA-56v6-2fhr-wxgq.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"}]}