Cross-site scripting in snipe-it - CVE-2026-44831
Published: May 11, 2026
snipe-it
snipe
Description
The vulnerability allows a remote user to execute arbitrary script code in a victim's browser.
The vulnerability exists due to cross-site scripting in the component checkout notes column when rendering stored notes content. A remote user can inject a malicious script into notes to execute arbitrary script code in a victim's browser.
User interaction is required, and users with component view access could be impacted.