Open redirect in snipe-it - #VU145095

 

Open redirect in snipe-it - #VU145095

Published: August 25, 2026


Vulnerability identifier: #VU145095
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-601
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to redirect a user to an arbitrary external URL.

The vulnerability exists due to url redirection to an untrusted site in SamlController::acs and the post-authentication redirect flow when processing an IdP-initiated SAML login with an attacker-controlled RelayState parameter. A remote attacker can send a crafted IdP-initiated SSO link to redirect a user to an arbitrary external URL.

Only deployments with SAML SSO enabled are vulnerable, and user interaction is required to visit the crafted link and complete the normal authentication flow.


Affected software

snipe-it

Remediation

Install security update from vendor's website.

snipe-it - update to 8.7.0

External References

Related Security Bulletins