A high-severity remote code execution flaw, CVE-2026-29514, affects NetBox 4.3.5 through 4.5.4 and allows authenticated users with exporttemplate or configtemplate permissions to execute arbitrary commands on the server. The bug lies in RenderTemplateMixin.get_environment_params(), where user-controlled JSON in environment_params can supply importable Python callables for Jinja2 settings such as finalize. By resolving values like subprocess.getoutput without an allowlist, NetBox lets attackers turn otherwise harmless template expressions into shell command execution as the NetBox service user.

See affected versions and whether adversaries are exploiting it.
5 events from the most recent confirmed update back to the earliest known activity.
A public CVE entry for CVE-2026-29514 described the affected versions, exploitation requirements, and the RenderTemplateMixin.get_environment_params() root cause. The record also linked to the blog post, GitHub issue, pull request, and VulnCheck advisory.
After receiving no maintainer response, the researcher publicly disclosed details of the NetBox vulnerability, including exploitation via the finalize parameter and impact on ExportTemplate and ConfigTemplate. The disclosure described how Jinja2 sandbox protections could be bypassed to execute shell commands as the NetBox service user.
The vulnerability was assigned identifier CVE-2026-29514 through VulnCheck. The CVE covers a high-severity remote code execution issue in NetBox's RenderTemplateMixin handling of environment_params.
The researcher reported the NetBox Jinja2 sandbox bypass and remote code execution issue to the project maintainers. The flaw affected NetBox versions 4.3.5 through 4.5.4 and allowed authenticated low-privilege users with relevant template permissions to achieve code execution.
In July 2025, a NetBox code change added Django import_string() resolution for the Jinja2 environment_params fields undefined and finalize without an allowlist. This created the condition that later enabled sandbox bypass and remote code execution.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcechocapikk.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.