Description
Snipe-IT versions before 8.7.0 contain a CSS injection vulnerability in the Custom CSS field due to incomplete sanitization that reverses HTML encoding on greater-than and double-quote characters. Superusers can plant malicious CSS payloads using @import and url() references to exfiltrate CSRF tokens from other superusers via attribute-selector rules, enabling account takeover.
Published: 2026-09-08
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Account takeover via CSRF token theft
Action: Immediate Patch
AI Analysis

Impact

Snipe-IT versions prior to 8.7.0 handle Custom CSS input without properly escaping the greater‑than (>) and double‑quote (") characters, allowing a superuser to inject arbitrary CSS. By embedding @import or url() references and crafting attribute‑selector rules, the attacker can read CSRF tokens stored in the browser context of other superusers and use those tokens to perform authenticated actions as those users, effectively hijacking their accounts.

Affected Systems

The vulnerability affects the Snipe‑IT asset management application supplied by grokability. All releases earlier than 8.7.0 are impacted; no more granular version ranges are specified by the CNA.

Risk and Exploitability

The CVSS score of 9.3 classifies this flaw as Critical, and the EPSS score is unknown. The flaw was not listed in the CISA KEV catalog. The likely attack vector is the web interface where Custom CSS can be submitted, requiring that the attacker has superuser authentication. Once injected, the attacker obtains an arbitrary other superuser’s CSRF token and can impersonate that account. The exploitation responsibility depends on the attacker’s ability to obtain superuser privileges or compromise an existing superuser account.

Generated by OpenCVE AI on September 8, 2026 at 18:12 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Snipe‑IT 8.7.0 or newer, which removes the problematic CSS sanitization code.
  • If an upgrade is delayed, temporarily revoke or restrict superuser permissions on all non‑essential users and audit existing Custom CSS for @import or url() patterns; delete any offending entries.
  • Introduce an application‑level filter that sanitizes Custom CSS input by escaping or removing '>' and '"' characters and rejects any @import or url() references, thereby preventing future injection.

Generated by OpenCVE AI on September 8, 2026 at 18:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 08 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
First Time appeared Grokability
Grokability snipe-it
Vendors & Products Grokability
Grokability snipe-it

Tue, 08 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Description Snipe-IT versions before 8.7.0 contain a CSS injection vulnerability in the Custom CSS field due to incomplete sanitization that reverses HTML encoding on greater-than and double-quote characters. Superusers can plant malicious CSS payloads using @import and url() references to exfiltrate CSRF tokens from other superusers via attribute-selector rules, enabling account takeover.
Title Snipe-IT before 8.7.0 CSS Injection via Custom CSS
First Time appeared Snipeitapp
Snipeitapp snipe-it
Weaknesses CWE-79
CPEs cpe:2.3:a:snipeitapp:snipe-it:*:*:*:*:*:*:*:*
Vendors & Products Snipeitapp
Snipeitapp snipe-it
References
Metrics cvssV3_1

{'score': 8.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N'}


Subscriptions

Grokability Snipe-it
Snipeitapp Snipe-it
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-08T15:30:34.120Z

Reserved: 2026-09-08T11:31:38.678Z

Link: CVE-2026-86738

cve-icon Vulnrichment

Updated: 2026-09-08T15:30:30.988Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T16:18:36.980

Modified: 2026-09-09T13:06:27.157

Link: CVE-2026-86738

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T18:15:15Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')