Server-Side Request Forgery (SSRF) in snipe-it - #VU145074

 

Server-Side Request Forgery (SSRF) in snipe-it - #VU145074

Published: August 25, 2026


Vulnerability identifier: #VU145074
CSH Severity: Low
CVSS v4: 5.9 [CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-918
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to access internal services and disclose sensitive information via server-side request forgery.

The vulnerability exists due to improper restriction of rendered transition IPv6 addresses in ExternalUrl validation rule in app/Rules/ExternalUrl.php when validating webhook URLs or resolved AAAA records. A remote privileged user can supply a specially crafted webhook URL containing an IPv6 transition address or a hostname resolving to one to access internal services and disclose sensitive information via server-side request forgery.

Exploitation is possible on NAT64-, 6to4-, or Teredo-enabled hosts and can target cloud instance metadata endpoints such as 169.254.169.254.


Affected software

snipe-it

Remediation

Install security update from vendor's website.

snipe-it - update to 8.7.0

External References

Related Security Bulletins