CVE-2026-62368
CVE-2026-62368
8.1
HighPublished:
Last updated:
Source:security-advisories@github.com
Analyzed
Weakness (CWE)
CVSS Vector
v3.1- Attack Vector
- Network
- Attack Complexity
- Low
- Privileges Required
- High
- User Interaction
- Required
- Scope
- Changed
- Confidentiality
- High
- Integrity
- High
- Availability
- None
Description
Snipe-IT is an IT asset/license management system. Prior to 8.7.0, a user with the customfields.create permission can store markup in CustomField.name, and app/Presenters/AssetPresenter.php assigns that value as an unescaped bootstrap-table header title. When another user opens an asset-list page associated with the fieldset, the stored markup executes on page load in that user's Snipe-IT session. This can expose same-origin data and perform authenticated actions with the victim's privileges, including privilege escalation when a superuser views the affected list. This issue is fixed in version 8.7.0.
References
security-advisories@github.com
https://github.com/grokability/snipe-it/commit/58754e4e3b86b58a0c4523012ef04a2ae990d2c8security-advisories@github.com
https://github.com/grokability/snipe-it/releases/tag/v8.7.0security-advisories@github.com
https://github.com/grokability/snipe-it/security/advisories/GHSA-p9h3-gvpq-5539134c704f-9b21-4f2e-91b3-4a467353bcc0
https://github.com/grokability/snipe-it/security/advisories/GHSA-p9h3-gvpq-5539