Stored JavaScript Injection in Snipe-IT Asset Management System
CVE-2026-61807
6.3MEDIUM
What is CVE-2026-61807?
A vulnerability in the Snipe-IT IT asset/license management system allows for stored JavaScript injection due to improper handling of manufacturer or supplier names. When an authenticated user views the affected pages, crafted names become part of an executable HTML string that can trigger unwanted JavaScript execution, potentially exposing sensitive session data. This risk was mitigated in version 8.6.2.
Affected Version(s)
snipe-it < 8.6.2
