Server-Side Request Forgery in Snipe-IT by Grokability
CVE-2026-86771
8.3HIGH
What is CVE-2026-86771?
Earlier versions of Snipe-IT (prior to 8.7.0) possess a vulnerability that allows attackers with 'users.edit' permission to execute server-side requests. This vulnerability arises from inadequate HTML-escaping of the 'employee_num' field in the PDF generator, enabling malicious users to inject image tags containing harmful HTTP(S) URLs. Once a victim interacts with the acceptance of an asset, these crafted URLs can trigger requests to internal services or external endpoints, potentially exposing sensitive data to unauthorized access.
Affected Version(s)
snipe-it 8.6.3 < 8.7.0
snipe-it 8.7.0
