CSV Formula Injection Vulnerability in Snipe-IT Asset Management
CVE-2026-86742
5.1MEDIUM
What is CVE-2026-86742?
The Snipe-IT asset management tool prior to version 8.7.0 contains a CSV formula injection vulnerability. This flaw arises from the improper handling of free-text fields in the 'unaccepted assets' acceptance report CSV export. An authenticated low-privilege user can manipulate fields to include formula elements that, when exported and opened in spreadsheet applications, can execute arbitrary commands or exfiltrate data. The vulnerability allows an attacker to craft malicious input that is executed as a formula in the context of the end-user's application, leading to significant data risks.
Affected Version(s)
snipe-it 0 < 8.7.0
snipe-it 8.7.0
