Skip to main content
Vulnerability Database/CVE-2024-56916

CVE-2024-56916: Netbox Configuration History XSS Vulnerability

CVE-2024-56916 is a cross-site scripting flaw in Netbox Community 4.1.7 affecting Configuration History functionality. Authenticated attackers can inject malicious JavaScript through banner fields. This post covers technical details, affected versions, impact assessment, and mitigation strategies.

Published:

CVE-2024-56916 Overview

CVE-2024-56916 is a stored cross-site scripting (XSS) vulnerability in NetBox Community version 4.1.7. The flaw resides in the Configuration History Add functionality, where the current value field renders user-supplied HTML without sanitization. An authenticated attacker can inject malicious JavaScript into any banner field. The payload executes when a victim edits an existing Configuration History version or attempts to add a new version. NetBox is a widely deployed IP address management (IPAM) and data center infrastructure management (DCIM) tool, making this weakness relevant to network operations teams.

Critical Impact

Authenticated attackers can execute arbitrary JavaScript in the browser context of NetBox administrators, enabling session theft, configuration tampering, and pivoting within the management interface.

Affected Products

  • NetBox Community 4.1.7
  • NetBox banner configuration fields
  • NetBox Configuration History module

Discovery Timeline

  • 2025-06-24 - CVE CVE-2024-56916 published to NVD
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2024-56916

Vulnerability Analysis

The vulnerability is a stored cross-site scripting flaw classified under [CWE-79]. NetBox's Configuration History feature stores administrator-defined values, including banner content, and later renders them back to the interface. The current value field of the Configuration History Add view fails to encode HTML entities before rendering. Any script tags or event handlers stored in a banner field are treated as executable markup when the page is rendered.

Because the payload persists in the configuration database, the attack is stored rather than reflected. Any authenticated user who opens the affected view triggers execution automatically. The impact scope changes across a trust boundary, meaning script executes in the context of the NetBox web application with the victim's privileges. Successful exploitation supports session hijacking, forced configuration changes, and abuse of NetBox's API tokens accessible from the same origin.

Root Cause

The root cause is missing output encoding on the current value field associated with banner configuration entries. The template renders stored HTML directly rather than escaping angle brackets and quote characters. This violates the principle of contextual output encoding for HTML sinks.

Attack Vector

An attacker requires an authenticated NetBox session with permission to modify banner configuration. The attacker submits a banner value containing a JavaScript payload. The payload is stored in the Configuration History. When another user, typically an administrator, opens the Add view or edits a prior Configuration History version, the payload executes in their browser.

The vulnerability mechanism is described in the public research repository. See the GitHub CVE-2024-56916 Research entry for the proof-of-concept walkthrough and the GitHub NetBox Release v4.1.7 notes for the affected build.

Detection Methods for CVE-2024-56916

Indicators of Compromise

  • Banner configuration entries containing <script> tags, on* event handlers, or javascript: URIs
  • Unexpected outbound requests from administrator browsers to attacker-controlled domains shortly after opening NetBox Configuration History views
  • Configuration History revisions authored by low-privilege accounts that modify banner fields

Detection Strategies

  • Query the NetBox database and API for banner field values, then flag entries containing HTML tags or JavaScript syntax
  • Review audit logs for Configuration History Add and edit events performed by non-administrative accounts
  • Inspect web server access logs for POST requests to configuration endpoints with payloads containing script markup

Monitoring Recommendations

  • Enable and centralize NetBox change-log events for all configuration and banner modifications
  • Monitor administrator browser sessions for anomalous API token usage or unexpected outbound requests originating from the NetBox origin
  • Alert on any modification to banner or Configuration History records made by accounts that do not normally administer NetBox

How to Mitigate CVE-2024-56916

Immediate Actions Required

  • Upgrade NetBox Community to a version later than 4.1.7 that includes the sanitization fix for the Configuration History current value field
  • Audit existing banner configuration and Configuration History entries for stored HTML or JavaScript payloads and remove any that are found
  • Restrict permissions to modify banner and configuration objects to a minimal set of trusted administrative accounts

Patch Information

Refer to the GitHub NetBox Release v4.1.7 page and subsequent NetBox releases for the corrected rendering behavior. Apply the latest stable release from the NetBox Community project and validate that the Configuration History view encodes HTML entities in the current value field.

Workarounds

  • Enforce a strict Content Security Policy (CSP) on the NetBox deployment to block inline script execution
  • Remove or restrict the edit banner and Configuration History permissions from user roles that do not require them
  • Require multi-factor authentication on all NetBox accounts to reduce the risk of low-privilege account compromise being used to plant payloads
bash
# Configuration example: restrict permissions and enforce CSP at the reverse proxy
# Nginx CSP header example for NetBox
add_header Content-Security-Policy "default-src 'self'; script-src 'self'; object-src 'none'; base-uri 'self';" always;

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.