CVE-2026-63498 — Snipe-IT is an IT asset/license management system.
Description
Snipe-IT is an IT asset/license management system. Prior to 8.7.0, the uploaded-files API endpoint GET /api/v1/{object_type}/{id}/files/{file_id} allows an authenticated user with file-management access to upload XML and XSLT attachments and request them with the inline=true parameter. The app/Http/Controllers/Api/UploadedFilesController.php show() path does not apply the safe-inline allowlist used by the equivalent web controller, so the browser can process an attacker-controlled xml-stylesheet reference and execute JavaScript generated by the stylesheet in the Snipe-IT origin. A victim who is authorized to view the object must open the attachment URL, after which the script can read same-origin data and perform authenticated actions with the victim's privileges. This issue is fixed in version 8.7.0.
CVSS v3.1 base metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:NMedium severity
Band computed from the CVSS base score, not the source's own label — so it means the same thing across every feed.
AV
Network
Attack Vector
AC
Low
Attack Complexity
PR
Low
Privileges Required
UI
Required
User Interaction
S
Changed
Scope
C
Low
Confidentiality
I
Low
Integrity
A
None
Availability
Affected
- Vendor
- snipeitapp
- Product
- snipe-it
Versions
- < 8.7.0
Stated as the source expressed them.
References
Related threats
same CWE or vendorCVE-2026-107801 — Jivejdon through 5.0 contains a stored cross-site scripting vulnerability that allows authenticated attackers to execute JavaScript by uploading at…
CVE-2026-107801 · 1h ago
CVE-2026-107800 — Jivejdon through 5.0 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject script into private short m…
CVE-2026-107800 · 1h ago
CVE-2026-107799 — Jivejdon through 5.0 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject script by posting unsanitiz…
CVE-2026-107799 · 1h ago
CVE-2026-107798 — jivejdon from commit 595d8d22 through commit ee67a65e contains a stored cross-site scripting vulnerability in the default-enabled TextStyle filter …
CVE-2026-107798 · 1h ago
CVE-2026-107797 — Jivejdon through 5.0 contains a reflected cross-site scripting vulnerability in application/message/postThread.jsp that allows attackers to inject …
CVE-2026-107797 · 1h ago
CVE-2026-107796 — Jivejdon from commit 5489372d through commit ee67a65e contains a reflected cross-site scripting vulnerability in application/query/taggedThreadList…
CVE-2026-107796 · 1h ago