OS Command Injection in snipe-it - #VU145072

 

OS Command Injection in snipe-it - #VU145072

Published: August 25, 2026


Vulnerability identifier: #VU145072
CSH Severity: Low
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-78
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to improper neutralization of special elements used in an os command in the backup restore functionality when streaming the SQL entry from an uploaded backup archive into the MySQL or MariaDB command-line client without binary mode. A remote privileged user can upload a crafted backup archive and trigger a restore to execute arbitrary code.

Exploitation requires a superadministrator session, backup upload and restore to be enabled, the mysql client to be installed, and the restore to proceed without the clean sanitizer parameter.


Affected software

snipe-it

Remediation

Install security update from vendor's website.

snipe-it - update to 8.7.0

External References

Related Security Bulletins