Packagist (Composer) package
snipe/snipe-it
pkg:composer/snipe/snipe-it
Vulnerabilities (50)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-61807 | Med | — | < 8.6.2 | 8.6.2 | Aug 19, 2026 | Snipe-IT is an IT asset/license management system. Prior to 8.6.2, a stored manufacturer or supplier name passed as the table component $name becomes data-selected-count-id in resources/views/partials/bootstrap-table.blade.php. Client-side code reads the browser-decoded countId, | |
| CVE-2026-55703 | Med | 4.3 | < 8.6.3 | 8.6.3 | Aug 19, 2026 | Snipe-IT is an IT asset/license management system. Prior to 8.6.3, any activated account can request /maintenances/{id} and read maintenance records for assets in the same company without asset or maintenance permission. app/Http/Controllers/MaintenancesController.php show() rend | |
| CVE-2026-55694 | Hig | — | < 8.6.3 | 8.6.3 | Aug 19, 2026 | Snipe-IT is an IT asset/license management system. Prior to 8.6.3, a restricted user can request /api/v1/users/{target_id}/eulas to obtain another user's randomized EULA filename and then download the signed file through /account/stored-eula-file/{filename}. The primary /stored-e | |
| CVE-2026-55643 | Hig | — | < 8.6.3 | 8.6.3 | Aug 19, 2026 | Snipe-IT is an IT asset/license management system. Prior to 8.6.3, a company-scoped user in FMCS floater mode can access users whose company_id is null because broad API queries and bulk web actions do not consistently apply isCurrentUserHasAccess. The /api/v1/users and /api/v1/u | |
| CVE-2026-44833 | Med | 5.9 | < 8.4.1 | 8.4.1 | May 26, 2026 | Snipe-IT is an IT asset/license management system. Prior to 8.4.1, an open redirect vulnerability in Snipe-IT allows attackers to redirect users to malicious sites via unvalidated HTTP Referer header stored in session variable. This vulnerability is fixed in 8.4.1. | |
| CVE-2026-44832 | Hig | 8.8 | < 8.4.1 | 8.4.1 | May 26, 2026 | Snipe-IT is an IT asset/license management system. Prior to 8.4.1, aAn authenticated user with only users.edit permission can escalate their own privileges to admin by sending a PATCH request to /api/v1/users/{id} with permissions[admin]=1. The API controller only strips the supe | |
| CVE-2026-44831 | Med | 4.8 | < 8.4.1 | 8.4.1 | May 26, 2026 | Snipe-IT is an IT asset/license management system. Prior to 8.4.1, users with component view access could be impacted by an unescaped notes column, resulting in cross-site scripting (XSS). This vulnerability is fixed in 8.4.1. | |
| CVE-2026-37709 | Cri | 9.8 | < 8.4.1 | 8.4.1 | May 7, 2026 | Insecure Permissions vulnerability in grokability snipe-it v.8.4.0 and before and fixed after 2026-03-10 commit 676a9958 allows a remote attacker to execute arbitrary code via the app/Http/Controllers/Api/UploadedFilesController.php component | |
| CVE-2025-15602 | Hig | 8.8 | < 8.3.7 | 8.3.7 | Mar 6, 2026 | Snipe-IT versions prior to 8.3.7 contain sensitive user attributes related to account privileges that are insufficiently protected against mass assignment. An authenticated, low-privileged user can craft a malicious API request to modify restricted fields of another user account, | |
| CVE-2025-65622 | Med | 5.4 | < 8.3.4 | 8.3.4 | Dec 1, 2025 | Snipe-IT before 8.3.4 allows stored XSS via the Locations "Country" field, enabling a low-privileged authenticated user to inject JavaScript that executes in another user's session. | |
| CVE-2025-65621 | Med | 5.4 | < 8.3.4 | 8.3.4 | Dec 1, 2025 | Snipe-IT before 8.3.4 allows stored XSS, allowing a low-privileged authenticated user to inject JavaScript that executes in an administrator's session, enabling privilege escalation. | |
| CVE-2025-64027 | Med | 6.1 | <= 8.3.4 | — | Nov 20, 2025 | Snipe-IT v8.3.4 (build 20218) contains a reflected cross-site scripting (XSS) vulnerability in the CSV Import workflow. When an invalid CSV file is uploaded, the application returns a progress_message value that is rendered as raw HTML in the admin interface. An attacker can inte | |
| CVE-2025-59713 | Med | 6.8 | < 8.1.18 | 8.1.18 | Sep 19, 2025 | Snipe-IT before 8.1.18 allows unsafe deserialization. | |
| CVE-2025-59712 | Med | 6.4 | < 8.1.18 | 8.1.18 | Sep 19, 2025 | Snipe-IT before 8.1.18 allows XSS. | |
| CVE-2025-47226 | Med | 5.0 | < 8.1.0 | 8.1.0 | May 2, 2025 | Grokability Snipe-IT before 8.1.0 has incorrect authorization for accessing asset information. | |
| CVE-2024-51093 | Hig | 8.7 | <= 7.0.13 | — | Nov 12, 2024 | Stored Cross-Site Scripting (XSS) vulnerability in Snipe-IT - v7.0.13 allows an attacker to upload a malicious XML file containing JavaScript code. This can lead to privilege escalation when the payload is executed, granting the attacker super admin permissions within the Snipe-I | |
| CVE-2024-48987 | Med | 6.6 | < 7.0.10 | 7.0.10 | Oct 11, 2024 | Snipe-IT before 7.0.10 allows remote code execution (associated with cookie serialization) when an attacker knows the APP_KEY. This is exacerbated by .env files, available from the product's repository, that have default APP_KEY values. | |
| CVE-2024-5685 | Hig | 7.6 | < 6.4.2 | 6.4.2 | Jun 14, 2024 | Users with "User:edit" and "Self:api" permissions can promote or demote themselves or other users by performing changes to the group's memberships via API call.This issue affects snipe-it: from v4.6.17 through v6.4.1. | |
| CVE-2023-5511 | Hig | 8.8 | < 6.2.3 | 6.2.3 | Oct 11, 2023 | Cross-Site Request Forgery (CSRF) in GitHub repository snipe/snipe-it prior to v.6.2.3. | |
| CVE-2023-5452 | Med | 5.4 | < 6.2.2 | 6.2.2 | Oct 6, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository snipe/snipe-it prior to v6.2.2. |
- affected < 8.6.2fixed 8.6.2
Snipe-IT is an IT asset/license management system. Prior to 8.6.2, a stored manufacturer or supplier name passed as the table component $name becomes data-selected-count-id in resources/views/partials/bootstrap-table.blade.php. Client-side code reads the browser-decoded countId,
- affected < 8.6.3fixed 8.6.3
Snipe-IT is an IT asset/license management system. Prior to 8.6.3, any activated account can request /maintenances/{id} and read maintenance records for assets in the same company without asset or maintenance permission. app/Http/Controllers/MaintenancesController.php show() rend
- affected < 8.6.3fixed 8.6.3
Snipe-IT is an IT asset/license management system. Prior to 8.6.3, a restricted user can request /api/v1/users/{target_id}/eulas to obtain another user's randomized EULA filename and then download the signed file through /account/stored-eula-file/{filename}. The primary /stored-e
- affected < 8.6.3fixed 8.6.3
Snipe-IT is an IT asset/license management system. Prior to 8.6.3, a company-scoped user in FMCS floater mode can access users whose company_id is null because broad API queries and bulk web actions do not consistently apply isCurrentUserHasAccess. The /api/v1/users and /api/v1/u
- affected < 8.4.1fixed 8.4.1
Snipe-IT is an IT asset/license management system. Prior to 8.4.1, an open redirect vulnerability in Snipe-IT allows attackers to redirect users to malicious sites via unvalidated HTTP Referer header stored in session variable. This vulnerability is fixed in 8.4.1.
- affected < 8.4.1fixed 8.4.1
Snipe-IT is an IT asset/license management system. Prior to 8.4.1, aAn authenticated user with only users.edit permission can escalate their own privileges to admin by sending a PATCH request to /api/v1/users/{id} with permissions[admin]=1. The API controller only strips the supe
- affected < 8.4.1fixed 8.4.1
Snipe-IT is an IT asset/license management system. Prior to 8.4.1, users with component view access could be impacted by an unescaped notes column, resulting in cross-site scripting (XSS). This vulnerability is fixed in 8.4.1.
- affected < 8.4.1fixed 8.4.1
Insecure Permissions vulnerability in grokability snipe-it v.8.4.0 and before and fixed after 2026-03-10 commit 676a9958 allows a remote attacker to execute arbitrary code via the app/Http/Controllers/Api/UploadedFilesController.php component
- affected < 8.3.7fixed 8.3.7
Snipe-IT versions prior to 8.3.7 contain sensitive user attributes related to account privileges that are insufficiently protected against mass assignment. An authenticated, low-privileged user can craft a malicious API request to modify restricted fields of another user account,
- affected < 8.3.4fixed 8.3.4
Snipe-IT before 8.3.4 allows stored XSS via the Locations "Country" field, enabling a low-privileged authenticated user to inject JavaScript that executes in another user's session.
- affected < 8.3.4fixed 8.3.4
Snipe-IT before 8.3.4 allows stored XSS, allowing a low-privileged authenticated user to inject JavaScript that executes in an administrator's session, enabling privilege escalation.
- affected <= 8.3.4
Snipe-IT v8.3.4 (build 20218) contains a reflected cross-site scripting (XSS) vulnerability in the CSV Import workflow. When an invalid CSV file is uploaded, the application returns a progress_message value that is rendered as raw HTML in the admin interface. An attacker can inte
- affected < 8.1.18fixed 8.1.18
Snipe-IT before 8.1.18 allows unsafe deserialization.
- affected < 8.1.18fixed 8.1.18
Snipe-IT before 8.1.18 allows XSS.
- affected < 8.1.0fixed 8.1.0
Grokability Snipe-IT before 8.1.0 has incorrect authorization for accessing asset information.
- affected <= 7.0.13
Stored Cross-Site Scripting (XSS) vulnerability in Snipe-IT - v7.0.13 allows an attacker to upload a malicious XML file containing JavaScript code. This can lead to privilege escalation when the payload is executed, granting the attacker super admin permissions within the Snipe-I
- affected < 7.0.10fixed 7.0.10
Snipe-IT before 7.0.10 allows remote code execution (associated with cookie serialization) when an attacker knows the APP_KEY. This is exacerbated by .env files, available from the product's repository, that have default APP_KEY values.
- affected < 6.4.2fixed 6.4.2
Users with "User:edit" and "Self:api" permissions can promote or demote themselves or other users by performing changes to the group's memberships via API call.This issue affects snipe-it: from v4.6.17 through v6.4.1.
- affected < 6.2.3fixed 6.2.3
Cross-Site Request Forgery (CSRF) in GitHub repository snipe/snipe-it prior to v.6.2.3.
- affected < 6.2.2fixed 6.2.2
Cross-site Scripting (XSS) - Stored in GitHub repository snipe/snipe-it prior to v6.2.2.
Page 1 of 3