Jinja2 · Jinja2 · CVE-2025-49142
**Name of the Vulnerable Software and Affected Versions**
Nautobot versions prior to 1.6.32
Nautobot versions prior to 2.4.10
**Description**
The issue arises from insufficient security configuration of the Jinja2 templating feature in Nautobot, which can be exploited by a malicious user to expose Secrets or modify data within Nautobot by bypassing object permissions. This can occur when templated content is rendered.
**Recommendations**
For versions prior to 1.6.32, update to version 1.6.32 or later to resolve the issue.
For versions prior to 2.4.10, update to version 2.4.10 or later to resolve the issue.
As a temporary workaround, consider configuring object permissions to limit certain actions to only trusted users, which can partially mitigate the vulnerability.