PT-2026-98145 · Snipe-It · Snipe-It
CVSS v3.1
8.7
High
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Snipe-IT versions prior to 8.7.0
Description
An authenticated user with file-management access can upload malicious XML and XSLT (Extensible Stylesheet Language Transformations) attachments. The API endpoint 'GET /api/v1/{object type}/{id}/files/{file id}' fails to apply a safe-inline allowlist when the
inline parameter is set to true. This allows the browser to process an attacker-controlled xml-stylesheet reference, leading to the execution of arbitrary JavaScript within the Snipe-IT origin. If an authorized victim opens the attachment URL, the script can read same-origin data and perform authenticated actions using the victim's privileges, potentially leading to administrative account compromise and exposure of sensitive asset, user, and license information.Recommendations
Update Snipe-IT to version 8.7.0.
As a temporary mitigation, restrict the use of the
inline parameter in the 'GET /api/v1/{object type}/{id}/files/{file id}' endpoint or disable XML upload capabilities in the configuration.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Snipe-It