PT-2026-57286 · Snipe-It · Snipe-It

CVE-2026-55466

·

Published

2026-07-10

·

Updated

2026-08-28

CVSS v3.1

8.7

High

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Snipe-IT versions prior to 8.6.2
Description An issue exists where the UploadFileRequest sanitizes SVG content only when PHP finfo reports image/svg+xml. Additionally, the UploadedFilesController serves attachments inline without utilizing StorageHelper::allowSafeInline(). This allows a low-privilege user to upload active XHTML or XML content that is subsequently served same-origin, leading to the execution of JavaScript in the browser of a user viewing the file.
Recommendations Update to version 8.6.2.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-55466
GHSA-JHPH-5Q74-PMFX

Affected Products

Snipe-It