CVE-2025-49143
unknown
CVSS v3
—
CVSS v2
—
VIR risk
—
Description
Nautobot may allows uploaded media files to be accessible without authentication
Predictions
Exploit likelihood
20%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No vendor mitigations ingested yet for this CVE. The mitigation-content worker queues fetches as references arrive — check back in a few minutes, or see the references list below.
References
- https://github.com/nautobot/nautobot/security/advisories/GHSA-rh67-4c8j-hjjh
- https://nvd.nist.gov/vuln/detail/CVE-2025-49143
- https://github.com/nautobot/nautobot/pull/6672
- https://github.com/nautobot/nautobot/pull/6703
- https://github.com/nautobot/nautobot/commit/9c892dc300429948a4714f743c9c2879d8987340
- https://github.com/nautobot/nautobot/commit/d99a53b065129cff3a0fa9abe7355a9ef1ad4c95
- https://github.com/nautobot/nautobot
Verify integrity in audit chain (admin only). AS-IS.