External Control of File Name or Path in snipe-it - #VU145090
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote user to read arbitrary server-readable files and issue arbitrary server-side HTTP requests.
The vulnerability exists due to external control of file name or path in the outbound mail markdown image handling chain when processing a user-supplied note field containing markdown image syntax. A remote user can submit a crafted note containing markdown image syntax to read arbitrary server-readable files and issue arbitrary server-side HTTP requests.
Exploitation requires a pending checkout acceptance, and the fetched content is embedded into the outbound notification email as a MIME part.