PT-2026-40720 · Nautobot+2 · Nautobot
Holmie
·
Published
2026-05-13
·
Updated
2026-05-29
·
CVE-2026-44798
CVSS v3.1
7.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H |
Name of the Vulnerable Software and Affected Versions
Nautobot versions prior to 2.4.33
Nautobot versions prior to 3.1.2
Description
A user with permissions to add or modify a GitRepository record can use the REST API to directly set the
current head field, which is not intended to be user-editable. This action may cause local clones of the repository to check out a commit other than the latest one on the specified branch, leading to a misleading state. Additionally, it could render the repository unusable if current head is set to a malformed value or a nonexistent commit hash.Recommendations
Update to version 2.4.33.
Update to version 3.1.2.
Carefully review and restrict permissions granted to users for creating and modifying GitRepository records.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Nautobot