Open redirect in snipe-it - #VU145095
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote attacker to redirect a user to an arbitrary external URL.
The vulnerability exists due to url redirection to an untrusted site in SamlController::acs and the post-authentication redirect flow when processing an IdP-initiated SAML login with an attacker-controlled RelayState parameter. A remote attacker can send a crafted IdP-initiated SSO link to redirect a user to an arbitrary external URL.
Only deployments with SAML SSO enabled are vulnerable, and user interaction is required to visit the crafted link and complete the normal authentication flow.