Cross-site scripting in snipe-it - CVE-2026-62368
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary script in a victim\'s session.
The vulnerability exists due to cross-site scripting in asset-list column headers when rendering a custom field name in the asset list. A remote privileged user can create a custom field with crafted HTML or JavaScript to execute arbitrary script in a victim\'s session.
User interaction is required to open an asset list page, and exploitation can lead to privilege escalation if a higher-privileged user\'s session is targeted.