Cross-site scripting in snipe-it - CVE-2026-55466

 

Cross-site scripting in snipe-it - CVE-2026-55466

Published: August 14, 2026


Vulnerability identifier: #VU142565
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: CVE-2026-55466
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary script in the victim\'s browser in the context of the application.

The vulnerability exists due to improper neutralization of script in uploaded XHTML content in the attachment upload and inline file serving functionality when uploading a crafted XML/XHTML attachment and accessing it with inline serving enabled. A remote user can upload a crafted attachment containing script and have it rendered inline as same-origin active content to execute arbitrary script in the victim\'s browser in the context of the application.

The issue occurs because XML/XHTML content can bypass the SVG sanitization path and is served with Content-Disposition: inline.


Affected software

snipe-it

How to mitigate CVE-2026-55466

Install security update from vendor's website.

snipe-it - update to 8.6.2

External References

Related Security Bulletins