CVE-2024-32979: Networktocode Nautobot

Medium severity, CVSS 6.1. EPSS: 0.5% chance of exploitation in the next 30 days.

Nautobot is a Network Source of Truth and Network Automation Platform built as a web application atop the Django Python framework with a PostgreSQL or MySQL database. It was discovered that due to improper handling and escaping of user-provided query parameters, a maliciously crafted Nautobot URL could potentially be used to execute a Reflected Cross-Site Scripting (Reflected XSS) attack against users. All filterable object-list views in Nautobot are vulnerable. This issue has been fixed in Nautobot versions 1.6.20 and 2.2.3. There are no known workarounds for this vulnerability.

Affected products

  • Networktocode Nautobot: from 1.5.0, before 1.6.20 (fixed in 1.6.20); from 2.0.0, before 2.2.3 (fixed in 2.2.3)

Published 2024-05-01. Last modified 2026-06-17.