Unsafe Deserialization in Snipe-IT Affects User Data Security
CVE-2025-59713

6.8MEDIUM

Key Information:

Vendor

Snipeitapp

Status
Vendor
CVE Published:
19 September 2025

What is CVE-2025-59713?

An unsafe deserialization vulnerability exists in Snipe-IT prior to version 8.1.18, which could potentially allow attackers to manipulate serialized data. This issue may lead to unauthorized access or execute arbitrary code, posing a risk to sensitive information and overall application integrity. Users are urged to update to the latest version to mitigate this vulnerability.

Affected Version(s)

Snipe-IT 0 < 8.1.18

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-59713 : Unsafe Deserialization in Snipe-IT Affects User Data Security