Path traversal in snipe-it - CVE-2026-55469
Published: August 14, 2026
Vulnerability details
The vulnerability allows a remote attacker to delete arbitrary files on the server filesystem.
The vulnerability exists due to path traversal in the CSV import image field when processing imported asset records and triggering image deletion. A remote attacker can inject a path traversal string into the image field via CSV import to delete arbitrary files on the server filesystem.
Exploitation requires the import and assets.update permissions.