Input validation error in snipe-it - #VU145108
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote user to modify inventory assignment records and cause inconsistent downstream processing.
The vulnerability exists due to improper input validation in the API checkout endpoints when processing checkout requests that reference soft-deleted users, assets, or locations. A remote user can send a specially crafted checkout request to modify inventory assignment records and cause inconsistent downstream processing.
Exploitation requires the relevant checkout permission for the affected resource.