Open redirect in snipe-it - CVE-2026-55461
Published: August 14, 2026
Vulnerability details
The vulnerability allows a remote attacker to redirect users to an external site.
The vulnerability exists due to improper control of redirect destinations in the user edit flow when processing a user edit request with an attacker-controlled Referer header and redirect_option=back. A remote attacker can cause a user to open the edit page and submit a normal edit action to redirect users to an external site.
User interaction is required, and exploitation depends on a logged-in user with permission to edit a user record performing the edit flow.