CVE-2023-25657 is a critical remote code execution (RCE) vulnerability affecting Nautobot versions prior to 1.5.7, stemming from improper sandboxing of Jinja2 template rendering. This allows an unauthenticated attacker to execute arbitrary code on the system. With a CVSS score of 9.8 (CRITICAL), the vulnerability has a network attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. While no active exploits are publicly known, and there is no exploit code available or significant community discussion, users are strongly advised to upgrade to Nautobot 1.5.7 or implement the provided configuration workaround.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.5.7CPE matchmatch criteria | cpe:2.3:a:networktocode:nautobot:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.