PT-2026-57290 · Snipe-It · Snipe-It
CVE-2026-55481
·
Published
2026-07-10
·
Updated
2026-08-28
CVSS v4.0
6.2
Medium
| Vector | AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N |
Name of the Vulnerable Software and Affected Versions
Snipe-IT versions prior to 8.6.2
Description
In the
default.blade.php file, the header color and related branding color settings are rendered within a CSS style block using HTML escaping that is insufficient for the CSS context. This allows a superadmin to inject arbitrary CSS, which affects authenticated users on subsequent page loads when the Content Security Policy is disabled.Recommendations
Update to version 8.6.2.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Snipe-It