CVE-2026-83801
### Impact _What kind of vulnerability is it? Who is impacted?_ It has two related instances that share the same root cause: a user-controlled model field is assigned verbatim to a form field's `help_text`, which is rendered with Django's `|safe` filter (`render_field.html`), bypassing auto-escaping. In both cases the script executes in the browser of any user who opens an affected create or edit form, **including administrators and superusers**. Because the payload runs in the victim's authenticated session, it can lead to actions performed as the victim, session/token theft, and further privilege escalation. Exploitation requires the victim to open an affected form. #### Relationship description A user who holds the add/change permission for Relationships (`extras.add_relationship` / `extras.change_relationship`) can set a Relationship's **description** to an HTML/JavaScript payload. That description is used as the help text of the relationship's form field and is rendered on the create/edit page of every object type the relationship applies to. #### Module Family name A user who holds the add/change permission for Module Families (`dcim.add_modulefamily` / `dcim.change_modulefamily`) can put a payload in a Module Family **name**, which is interpolated into the `module_family` field's help text on the Module "Install module" form for any module bay assigned to that family. ### Patches _Has the problem been patched? What versions should users upgrade to?_ Fixes are available in Nautobot v2.4.37+ & v3.1.8+ > Note: The underlying weakness exists in earlier EOL versions of Nautobot (v1.x). Users on those older EOL versions are highly encouraged to upgrade to a supported version. ### Workarounds _Is there a way for users to fix or remediate the vulnerability without upgrading?_ There is no configuration-only fix. To remediate without upgrading: - Restrict the `extras.add_relationship` / `extras.change_relationship` and `dcim.add_modulefamily` / `dcim.change
Properties
- ghsa_id
- GHSA-56v6-2fhr-wxgq
- severity
- medium
- summary
- Nautobot: Stored cross-site scripting (XSS) in object create/edit form help text
- cvss_score
- 5.4
- cve_id
- CVE-2026-83801
- cvss_vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
- signal_observed_at
- 2026-09-23T04:35:57+00:00
- is_ghsa_only
- false
- ghsa_published
- 2026-09-22T20:37:30Z
- source_url
- https://github.com/advisories/GHSA-56v6-2fhr-wxgq
- ghsa_updated
- 2026-09-22T20:37:33Z
Related Entities (4)
HAS_WEAKNESS (1)
REPORTED_BY (1)
VULNERABLE_TO (1)
AFFECTS (1)
Explore deeper with Ninja Signal's threat intelligence graph