PT-2025-24685 · Jinja2+1 · Jinja2+1

Mzbroch

·

Published

2025-06-10

·

Updated

2025-08-21

·

CVE-2025-49142

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Nautobot versions prior to 1.6.32 Nautobot versions prior to 2.4.10
Description The issue arises from insufficient security configuration of the Jinja2 templating feature in Nautobot, which can be exploited by a malicious user to expose Secrets or modify data within Nautobot by bypassing object permissions. This can occur when templated content is rendered.
Recommendations For versions prior to 1.6.32, update to version 1.6.32 or later to resolve the issue. For versions prior to 2.4.10, update to version 2.4.10 or later to resolve the issue. As a temporary workaround, consider configuring object permissions to limit certain actions to only trusted users, which can partially mitigate the vulnerability.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-49142
GHSA-WJW6-95H5-4JPX
PYSEC-2025-74
PYSEC-2025-79

Affected Products

Jinja2
Nautobot