Description
Snipe-IT versions before 8.7.0 fail to sanitize the category EULA text field before rendering it in checkout confirmation emails. Attackers with low-privilege permissions can inject markdown image syntax or raw HTML img tags pointing to local files or remote URLs, which the mail auto-embed library resolves server-side and returns as email attachments, exfiltrating sensitive files like .env credentials and enabling SSRF attacks.
Published: 2026-09-09
Score: 8.4 High
EPSS: < 1% Very Low
KEV: No
Impact: Arbitrary File Read and SSRF via Category EULA
Action: Immediate Patch
AI Analysis

Impact

Prior to version 8.7.0, the Snipe‑IT application does not sanitize the EULA text field for category settings. A user with low‑privilege rights can inject markdown image syntax or raw HTML image tags that reference local files or remote URLs. When the application generates a checkout confirmation email, its auto‑embed library resolves those references server‑side and attaches the referenced content to the email before sending. This allows the attacker to read sensitive files such as .env credentials from the server’s filesystem and to direct the mail system to fetch arbitrary external resources, effectively enabling server‑side request forgery (SSRF).

Affected Systems

The vulnerability exists in the Snipe‑IT web application released by grokability. All releases prior to 8.7.0 contain the unfiltered EULA processing code and are therefore susceptible.

Risk and Exploitability

The CVSS score of 8.4 indicates high severity. Although the EPSS score is not reported and the vulnerability is not listed in the CISA KEV catalog, its exploitation requires only low‑privilege access and allows the exfiltration of confidential files via outbound email attachments. The risk is significant for deployments where users receive these emails or where local email servers are used, as attackers could read sensitive secrets or perform SSRF attacks without additional privileges.

Generated by OpenCVE AI on September 9, 2026 at 15:48 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Snipe‑IT application to version 8.7.0 or later to eliminate the unfiltered EULA processing path.
  • Restrict the ability to edit category EULA text to users with the highest privilege levels and, if possible, disable markdown support for that field.
  • Disable the email auto‑embed feature or enforce strict sanitization of image URLs so that only safe, authenticated resources can be embedded.
  • Regularly monitor outbound email logs for unexpected attachments that may contain sensitive system files.

Generated by OpenCVE AI on September 9, 2026 at 15:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
First Time appeared Grokability
Grokability snipe-it
Vendors & Products Grokability
Grokability snipe-it

Wed, 09 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
Description Snipe-IT versions before 8.7.0 fail to sanitize the category EULA text field before rendering it in checkout confirmation emails. Attackers with low-privilege permissions can inject markdown image syntax or raw HTML img tags pointing to local files or remote URLs, which the mail auto-embed library resolves server-side and returns as email attachments, exfiltrating sensitive files like .env credentials and enabling SSRF attacks.
Title Snipe-IT before 8.7.0 Arbitrary File Read and SSRF via Category EULA
First Time appeared Snipeitapp
Snipeitapp snipe-it
Weaknesses CWE-73
CPEs cpe:2.3:a:snipeitapp:snipe-it:*:*:*:*:*:*:*:*
Vendors & Products Snipeitapp
Snipeitapp snipe-it
References
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N'}

cvssV4_0

{'score': 8.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N'}


Subscriptions

Grokability Snipe-it
Snipeitapp Snipe-it
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-09T14:26:11.177Z

Reserved: 2026-09-08T11:31:38.679Z

Link: CVE-2026-86741

cve-icon Vulnrichment

Updated: 2026-09-09T14:26:07.215Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T14:17:22.680

Modified: 2026-09-14T20:48:28.010

Link: CVE-2026-86741

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T18:45:17Z

Weaknesses
  • CWE-73

    External Control of File Name or Path