Description
Snipe-IT is an IT asset/license management system. Prior to 8.4.1, users with component view access could be impacted by an unescaped notes column, resulting in cross-site scripting (XSS). This vulnerability is fixed in 8.4.1.
References (2)
Core 2
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/grokability/snipe-it/security/advisories/GHSA-r42m-953q-6vjx
X_Refsource_Misc x_refsource_misc
https://github.com/grokability/snipe-it/commit/28f493d84d057895fbb93b6570e7393a2c2fa438
Scores
CVSS v3
4.8
EPSS
0.0022
EPSS Percentile
12.1%
Attack Vector
ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-79
Status
published
Products (3)
grokability/snipe-it
< 8.4.1
snipe/snipe-it
0 - 8.4.1Packagist
snipeitapp/snipe-it
< 8.4.1
Published
May 26, 2026
Tracked Since
May 27, 2026