CVE-2024-56916 Overview
CVE-2024-56916 is a stored cross-site scripting (XSS) vulnerability in NetBox Community version 4.1.7. The flaw resides in the Configuration History Add functionality, where the current value field renders user-supplied HTML without sanitization. An authenticated attacker can inject malicious JavaScript into any banner field. The payload executes when a victim edits an existing Configuration History version or attempts to add a new version. NetBox is a widely deployed IP address management (IPAM) and data center infrastructure management (DCIM) tool, making this weakness relevant to network operations teams.
Critical Impact
Authenticated attackers can execute arbitrary JavaScript in the browser context of NetBox administrators, enabling session theft, configuration tampering, and pivoting within the management interface.
Affected Products
- NetBox Community 4.1.7
- NetBox banner configuration fields
- NetBox Configuration History module
Discovery Timeline
- 2025-06-24 - CVE CVE-2024-56916 published to NVD
- 2026-06-17 - Last updated in NVD database
Technical Details for CVE-2024-56916
Vulnerability Analysis
The vulnerability is a stored cross-site scripting flaw classified under [CWE-79]. NetBox's Configuration History feature stores administrator-defined values, including banner content, and later renders them back to the interface. The current value field of the Configuration History Add view fails to encode HTML entities before rendering. Any script tags or event handlers stored in a banner field are treated as executable markup when the page is rendered.
Because the payload persists in the configuration database, the attack is stored rather than reflected. Any authenticated user who opens the affected view triggers execution automatically. The impact scope changes across a trust boundary, meaning script executes in the context of the NetBox web application with the victim's privileges. Successful exploitation supports session hijacking, forced configuration changes, and abuse of NetBox's API tokens accessible from the same origin.
Root Cause
The root cause is missing output encoding on the current value field associated with banner configuration entries. The template renders stored HTML directly rather than escaping angle brackets and quote characters. This violates the principle of contextual output encoding for HTML sinks.
Attack Vector
An attacker requires an authenticated NetBox session with permission to modify banner configuration. The attacker submits a banner value containing a JavaScript payload. The payload is stored in the Configuration History. When another user, typically an administrator, opens the Add view or edits a prior Configuration History version, the payload executes in their browser.
The vulnerability mechanism is described in the public research repository. See the GitHub CVE-2024-56916 Research entry for the proof-of-concept walkthrough and the GitHub NetBox Release v4.1.7 notes for the affected build.
Detection Methods for CVE-2024-56916
Indicators of Compromise
- Banner configuration entries containing <script> tags, on* event handlers, or javascript: URIs
- Unexpected outbound requests from administrator browsers to attacker-controlled domains shortly after opening NetBox Configuration History views
- Configuration History revisions authored by low-privilege accounts that modify banner fields
Detection Strategies
- Query the NetBox database and API for banner field values, then flag entries containing HTML tags or JavaScript syntax
- Review audit logs for Configuration History Add and edit events performed by non-administrative accounts
- Inspect web server access logs for POST requests to configuration endpoints with payloads containing script markup
Monitoring Recommendations
- Enable and centralize NetBox change-log events for all configuration and banner modifications
- Monitor administrator browser sessions for anomalous API token usage or unexpected outbound requests originating from the NetBox origin
- Alert on any modification to banner or Configuration History records made by accounts that do not normally administer NetBox
How to Mitigate CVE-2024-56916
Immediate Actions Required
- Upgrade NetBox Community to a version later than 4.1.7 that includes the sanitization fix for the Configuration History current value field
- Audit existing banner configuration and Configuration History entries for stored HTML or JavaScript payloads and remove any that are found
- Restrict permissions to modify banner and configuration objects to a minimal set of trusted administrative accounts
Patch Information
Refer to the GitHub NetBox Release v4.1.7 page and subsequent NetBox releases for the corrected rendering behavior. Apply the latest stable release from the NetBox Community project and validate that the Configuration History view encodes HTML entities in the current value field.
Workarounds
- Enforce a strict Content Security Policy (CSP) on the NetBox deployment to block inline script execution
- Remove or restrict the edit banner and Configuration History permissions from user roles that do not require them
- Require multi-factor authentication on all NetBox accounts to reduce the risk of low-privilege account compromise being used to plant payloads
# Configuration example: restrict permissions and enforce CSP at the reverse proxy
# Nginx CSP header example for NetBox
add_header Content-Security-Policy "default-src 'self'; script-src 'self'; object-src 'none'; base-uri 'self';" always;
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.