Skip to main content
Vulnerability Database/CVE-2026-104073

CVE-2026-104073: NetBox Template Injection XSS Vulnerability

CVE-2026-104073 is a server-side template injection flaw in NetBox that enables low-privileged attackers to steal session cookies and API tokens from other users. This article covers the technical details, affected versions, and mitigation strategies.

Published:

CVE-2026-104073 Overview

CVE-2026-104073 is a server-side template injection (SSTI) vulnerability affecting NetBox versions 2.9.5 through versions prior to 4.7.0. The flaw allows a low-privileged user holding the Can add custom links permission to inject Jinja2 templates that expose the raw Django HttpRequest object. Attackers can craft a custom link that embeds request.COOKIES['sessionid'] or a user's API token into an img tag src attribute. The payload bypasses the clean_html sanitizer and auto-exfiltrates credentials to an attacker-controlled host when a privileged user renders the affected object. Successful exploitation enables full account takeover, including administrative accounts [CWE-79].

Critical Impact

A low-privileged NetBox user can hijack administrator sessions and API tokens, achieving complete account takeover of the NetBox instance.

Affected Products

  • NetBox versions 2.9.5 through versions prior to 4.7.0
  • NetBox self-hosted deployments exposing the custom links feature
  • NetBox instances where non-admin roles have been granted the Can add custom links permission

Discovery Timeline

  • 2026-10-06 - CVE-2026-104073 published to NVD
  • 2026-10-07 - Last updated in NVD database

Technical Details for CVE-2026-104073

Vulnerability Analysis

NetBox's custom links feature allows users with the appropriate permission to define Jinja2 templates that render into object detail pages. The template rendering context exposes the full Django HttpRequest object, which carries session cookies and authentication material belonging to the viewing user. Because the context is rendered in the browser of whichever user views the object, a low-privileged attacker can store a payload that executes with the viewing user's credentials.

The output of the custom link template is passed through clean_html for sanitization, but the sanitizer does not strip template-constructed img src URLs that reference remote hosts. When the browser loads the attacker's img tag, it issues an outbound GET request carrying the victim's session ID or API token in the URL path or query string. The attacker then replays those credentials against the NetBox API or web interface to assume the victim's role.

Root Cause

The root cause is improper separation between user-controlled template content and sensitive runtime objects. The Jinja2 rendering context should expose only object-level attributes required for link construction. Exposing request, including request.COOKIES and token-bearing headers, violates least privilege and converts a formatting feature into a credential disclosure primitive. The clean_html post-processing step provides insufficient defense because exfiltration occurs through legitimate HTML elements whose attribute values are already attacker-controlled.

Attack Vector

The attack requires an authenticated session with the Can add custom links permission and relies on a privileged user subsequently viewing an object that renders the malicious link. The attacker creates a custom link whose template body builds an img element whose src points to an attacker-controlled server, concatenated with request.COOKIES['sessionid'] or an API token value. No further interaction from the attacker is required once the payload is stored. See the VulnCheck Advisory: NetBox Session Hijacking and GitHub Issue #22607 for the full technical write-up.

// No verified public exploit code is published.
// See the referenced advisories for proof-of-concept details.

Detection Methods for CVE-2026-104073

Indicators of Compromise

  • Outbound HTTP or HTTPS requests from user browsers to unrecognized domains containing long opaque strings in the URL path, consistent with session IDs or API tokens.
  • New or modified entries in the NetBox extras_customlink table whose link_text or link_url fields contain Jinja2 expressions referencing request, COOKIES, or sessionid.
  • NetBox audit log entries showing custom link creation by non-administrative accounts shortly before anomalous administrator API activity.

Detection Strategies

  • Query the NetBox database for custom link templates whose body contains the substrings request., COOKIES, sessionid, or token.
  • Inspect web server and reverse proxy logs for referer headers pointing to NetBox object pages that trigger third-party image loads.
  • Correlate custom link creation events with subsequent API token usage from new source IP addresses to identify replay of stolen credentials.

Monitoring Recommendations

  • Alert on any assignment of the extras.add_customlink permission to non-administrative roles or users.
  • Monitor egress traffic from workstations used by NetBox administrators for connections to domains outside the organizational allowlist that originate from NetBox object pages.
  • Enable and centrally review NetBox change logging to track creation and modification of custom link objects.

How to Mitigate CVE-2026-104073

Immediate Actions Required

  • Upgrade NetBox to version 4.7.0 or later, which removes the raw HttpRequest object from the Jinja2 custom link context.
  • Audit all existing custom link definitions and remove any template that references request, COOKIES, sessionid, token, or external URLs.
  • Revoke and rotate NetBox API tokens for any user who may have viewed an object containing an attacker-controlled custom link.
  • Review role assignments and remove the Can add custom links permission from accounts that do not require it.

Patch Information

The fix is included in NetBox Release v4.7.0. Implementation details are available in GitHub Pull Request #22616, which restricts the template rendering context and hardens output sanitization. Administrators running any version from 2.9.5 through versions prior to 4.7.0 should prioritize this upgrade.

Workarounds

  • Restrict the extras.add_customlink permission to trusted administrators until the upgrade can be applied.
  • Delete any custom link whose template content cannot be verified as safe.
  • Enforce short NetBox session lifetimes and short API token expirations to reduce the value of exfiltrated credentials.
  • Deploy an egress proxy or Content Security Policy that blocks image loads from untrusted domains on NetBox pages.
bash
# Example: audit custom links for suspicious template content
psql -U netbox -d netbox -c \
  "SELECT id, name, link_text, link_url FROM extras_customlink \
   WHERE link_text ILIKE '%request%' \
      OR link_text ILIKE '%cookies%' \
      OR link_text ILIKE '%sessionid%' \
      OR link_url  ILIKE '%request%' \
      OR link_url  ILIKE '%cookies%' \
      OR link_url  ILIKE '%sessionid%';"

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.