CVE-2026-55452

HIGH

Snipe-IT: CSV formula injection in Activity Report export

Title source: cna
STIX 2.1

Description

Snipe-IT is an IT asset/license management system. Prior to 8.5.0, Actionlog::logaction() stores the request User-Agent header and ReportsController::postActivityReport() writes that value to the Activity Report CSV without formula escaping, allowing a low-privileged authenticated user to store a formula-like User-Agent that may execute when a report viewer opens the exported CSV in spreadsheet software. This issue is fixed in version 8.5.0.

Scores

CVSS v3 7.3
EPSS 0.0023
EPSS Percentile 14.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-1236
Status published
Products (2)
grokability/snipe-it < 8.5.0
snipeitapp/snipe-it < 8.5.0
Published Jul 10, 2026
Tracked Since Jul 11, 2026