Snipe-IT Vulnerabilities: RCE and CSS Injection Risks Identified

Snipe-IT Vulnerabilities: RCE and CSS Injection Risks Identified

First seen 9 Sep 2026, 10:45 UTC www.vulncheck.com 57.1

Article Content

Browse articles
ThreatCluster

Two critical vulnerabilities have been discovered in Snipe-IT versions prior to 8.7.0. The first, a remote code execution (RCE) vulnerability, is due to improper handling of backup restores, categorized as CWE-78. The second vulnerability allows CSS injection through custom CSS, classified as CWE-79. These vulnerabilities affect all versions before 8.7.0, potentially allowing attackers to execute arbitrary code or inject malicious scripts. The vulnerabilities have been documented in GitHub Security Advisories (GHSA-x53f-48vj-c5fc and GHSA-pvcw-mp8q-mj39). Users are urged to upgrade to version 8.7.0 or later to mitigate these risks. As of now, there is no indication of active exploitation in the wild, but the vulnerabilities are significant enough to warrant immediate attention.

Key Points: • Two vulnerabilities in Snipe-IT before version 8.7.0: RCE and CSS injection. • RCE vulnerability allows arbitrary code execution via backup restore. • CSS injection vulnerability enables script injection through custom CSS.

Ask AI about this cluster

Timeline

2026-09-09
Vulnerabilities disclosed
Snipe-IT vulnerabilities (RCE and CSS injection) were disclosed, affecting all versions before 8.7.0.
VulnCheck
2026-09-09
Advisory published
GitHub Security Advisories published details on the vulnerabilities, urging users to upgrade.
VulnCheck