Description
Snipe-IT is an IT asset/license management system. Prior to 8.6.2, UploadFileRequest sanitizes SVG content only when PHP finfo reports image/svg+xml and UploadedFilesController serves attachments inline without using StorageHelper::allowSafeInline(), allowing a low-privilege user to upload active XHTML or XML content that is later served same-origin and executes JavaScript in a viewer’s browser. This issue is fixed in version 8.6.2.
References (3)
Core 3
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/grokability/snipe-it/security/advisories/GHSA-jhph-5q74-pmfx
X_Refsource_Misc x_refsource_misc
https://github.com/grokability/snipe-it/commit/000cea0a622d586366cf60d2240c7c2a4b17c955
X_Refsource_Misc x_refsource_misc
https://github.com/grokability/snipe-it/releases/tag/v8.6.2
Scores
CVSS v3
8.7
EPSS
0.0035
EPSS Percentile
27.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-79
Status
published
Products (2)
grokability/snipe-it
< 8.6.2
snipeitapp/snipe-it
< 8.6.2
Published
Jul 10, 2026
Tracked Since
Jul 11, 2026