Cross-site scripting in snipe-it - #VU145113
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary script in a victim\'s browser.
The vulnerability exists due to improper neutralization of input during web page generation in DepartmentPresenter::formattedNameLink() when rendering department names on the /account/view-assets page for users without the departments.view permission. A remote user can store a malicious script payload in a department name to execute arbitrary script in a victim\'s browser.
User interaction is required, and the payload executes when a member of the affected department loads their \"My Assets\" page.