Arbitrary File Read and SSRF in Snipe-IT by Snipe-IT
CVE-2026-86741
8.4HIGH
What is CVE-2026-86741?
Snipe-IT versions prior to 8.7.0 are vulnerable due to insufficient sanitization of the category EULA text field in checkout confirmation emails. This allows attackers with low-privilege permissions to inject markdown image syntax or HTML img tags that reference local files or remote URLs. The email system's auto-embed feature processes these references server-side, potentially resulting in the leakage of sensitive information such as .env credentials and enabling server-side request forgery (SSRF) attacks.
Affected Version(s)
snipe-it 0 < 8.7.0
snipe-it 8.7.0
