Bug 2436434 (CVE-2025-69848) - CVE-2025-69848 netbox: Netbox Cross site scripting
Summary: CVE-2025-69848 netbox: Netbox Cross site scripting
Keywords:
Status: NEW
Alias: CVE-2025-69848
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2436610
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-02-03 19:02 UTC by OSIDB Bzimport
Modified: 2026-02-04 00:55 UTC (History)
0 users

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-02-03 19:02:55 UTC
NetBox is an open-source infrastructure resource modeling and IP address management platform. A reflected cross-site scripting (XSS) vulnerability exists in versions 2.11.0 through 3.7.x in the ProtectedError handling logic, where object names are included in HTML error messages without proper escaping. This allows user-controlled content to be rendered in the web interface when a delete operation fails due to protected relationships, potentially enabling execution of arbitrary client-side code in the context of a privileged user.


Note You need to log in before you can comment on or make changes to this bug.