VYPR
Medium severity5.9NVD Advisory· Published Jun 10, 2025· Updated Jun 17, 2026

CVE-2025-49143

CVE-2025-49143

Description

Nautobot is a Network Source of Truth and Network Automation Platform. Prior to v2.4.10 and v1.6.32 , files uploaded by users to Nautobot's MEDIA_ROOT directory, including DeviceType image attachments as well as images attached to a Location, Device, or Rack, are served to users via a URL endpoint that was not enforcing user authentication. As a consequence, such files can be retrieved by anonymous users who know or can guess the correct URL for a given file. Nautobot v2.4.10 and v1.6.32 address this issue by adding enforcement of Nautobot user authentication to this endpoint.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
nautobotPyPI
< 1.6.321.6.32
nautobotPyPI
>= 2.0.0, < 2.4.102.4.10

Affected products

3
  • Nautobot/Nautobot2 versions
    cpe:2.3:a:networktocode:nautobot:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:networktocode:nautobot:*:*:*:*:*:*:*:*range: <1.6.32
    • (no CPE)range: < 1.6.32
  • ghsa-coords
    Range: < 1.6.32

Patches

Vulnerability mechanics

References

7

News mentions

0

No linked articles in our index yet.