Medium severity5.9GHSA Advisory· Published May 26, 2026· Updated May 26, 2026
CVE-2026-44833
CVE-2026-44833
Description
Snipe-IT is an IT asset/license management system. Prior to 8.4.1, an open redirect vulnerability in Snipe-IT allows attackers to redirect users to malicious sites via unvalidated HTTP Referer header stored in session variable. This vulnerability is fixed in 8.4.1.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
snipe/snipe-itPackagist | < 8.4.1 | 8.4.1 |
Affected products
2- Range: < 8.4.1
Patches
Vulnerability mechanics
References
4- github.com/grokability/snipe-it/commit/e37649212861a337e68a624e589c3540b7a82373nvdPatchWEB
- github.com/grokability/snipe-it/security/advisories/GHSA-mghp-5cq4-v6mgnvdPatchVendor AdvisoryWEB
- github.com/advisories/GHSA-mghp-5cq4-v6mgghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-44833ghsaADVISORY
News mentions
0No linked articles in our index yet.