PT-2026-98145 · Snipe-It · Snipe-It

·

CVE-2026-63498

·

Published

2026-09-24

·

Updated

2026-09-28

CVSS v3.1

8.7

High

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Snipe-IT versions prior to 8.7.0
Description An authenticated user with file-management access can upload malicious XML and XSLT (Extensible Stylesheet Language Transformations) attachments. The API endpoint 'GET /api/v1/{object type}/{id}/files/{file id}' fails to apply a safe-inline allowlist when the inline parameter is set to true. This allows the browser to process an attacker-controlled xml-stylesheet reference, leading to the execution of arbitrary JavaScript within the Snipe-IT origin. If an authorized victim opens the attachment URL, the script can read same-origin data and perform authenticated actions using the victim's privileges, potentially leading to administrative account compromise and exposure of sensitive asset, user, and license information.
Recommendations Update Snipe-IT to version 8.7.0. As a temporary mitigation, restrict the use of the inline parameter in the 'GET /api/v1/{object type}/{id}/files/{file id}' endpoint or disable XML upload capabilities in the configuration.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-63498
GHSA-396X-XMVH-P563

Affected Products

Snipe-It