Remote Code Execution Vulnerability in Snipe-IT Affected by Backup File Manipulation
CVE-2025-63601

9.9CRITICAL

Key Information:

Vendor

Snipe-IT

Status
Vendor
CVE Published:
5 November 2025

What is CVE-2025-63601?

Snipe-IT versions prior to 8.3.3 are vulnerable to a remote code execution issue that enables authenticated attackers to upload crafted backup files. These malicious files can contain arbitrary code, leading to unauthorized command execution within the system. This vulnerability highlights the critical importance of secure file handling and the need for immediate updates to protect against potential exploits.

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-63601 : Remote Code Execution Vulnerability in Snipe-IT Affected by Backup File Manipulation