Description
Snipe-IT through 8.6.3 does not neutralize formula elements in the "unaccepted assets" acceptance report CSV export. ReportsController::postAssetAcceptanceReport builds the CSV by hand (stripping commas and joining rows manually) and, unlike the six sibling exports in the same controller, never applies League\Csv\EscapeFormula or honors the config('app.escape_formulas') setting. An authenticated low-privilege user with ordinary create/edit rights on any record whose free-text fields appear in the report (asset name/tag, company name, category, model, or assignee display name) can set such a field to a value beginning with =, +, -, @, tab, or CR. When a user with reports.view privileges requests the export (POST /reports/unaccepted_assets) for a pending checkout acceptance referencing the poisoned record and opens the resulting CSV in Excel, LibreOffice Calc, or Google Sheets, the injected content is evaluated as a formula in the downloader's spreadsheet context, enabling data exfiltration (e.g., HYPERLINK/WEBSERVICE) or, on legacy Windows Excel configurations, DDE command execution. Fixed in 8.7.0.
Published: 2026-09-09
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Spreadsheet formula injection that can lead to data exfiltration or client‑side code execution
Action: Apply patch
AI Analysis

Impact

Snipe‑IT versions prior to 8.7.0 generate the unaccepted assets acceptance report CSV without escaping spreadsheet formula characters. An authenticated user with basic create/edit rights can set a free‑text field (such as asset name, company name, category, model, or assignee display name) to a value that starts with a formula indicator such as =, +, -, @, a tab, or a carriage return. When a user with reports.view privileges exports the report and the recipient opens the CSV in Excel, LibreOffice Calc or Google Sheets, the injected content is interpreted as a spreadsheet formula, enabling the attacker to exfiltrate data or, on legacy Windows Excel configurations, trigger DDE command execution.

Affected Systems

Snipe‑IT installations on web servers running the application, specifically versions up to and including 8.6.3. The vulnerability exists in the POST /reports/unaccepted_assets endpoint, which produces the CSV file that is transmitted to users.

Risk and Exploitability

The CVSS base score of 5.1 indicates a moderate overall risk. EPSS is not available and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires the attacker to be authenticated with both record‑edit and reports.view privileges. It then depends on the victim opening the exported CSV in a spreadsheet application. The impact is data exfiltration via spreadsheet formulas or, in some legacy configurations, client‑side code execution. Because the attack vector relies on user interaction, the overall risk is moderate unless the spreadsheet export is frequently processed by users.

Generated by OpenCVE AI on September 9, 2026 at 16:10 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Snipe‑IT to 8.7.0 or later, where the export routine escapes spreadsheet formula characters
  • Restrict free‑text asset fields for low‑privilege users or add server‑side validation to reject entries that start with =, +, -, @, a tab, or a carriage return
  • Enable the app.escape_formulas configuration setting or modify the export routine to use League\\Csv\\EscapeFormula, ensuring any formula content is prefixed with an apostrophe before delivery

Generated by OpenCVE AI on September 9, 2026 at 16:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
Description Snipe-IT through 8.6.3 does not neutralize formula elements in the "unaccepted assets" acceptance report CSV export. ReportsController::postAssetAcceptanceReport builds the CSV by hand (stripping commas and joining rows manually) and, unlike the six sibling exports in the same controller, never applies League\Csv\EscapeFormula or honors the config('app.escape_formulas') setting. An authenticated low-privilege user with ordinary create/edit rights on any record whose free-text fields appear in the report (asset name/tag, company name, category, model, or assignee display name) can set such a field to a value beginning with =, +, -, @, tab, or CR. When a user with reports.view privileges requests the export (POST /reports/unaccepted_assets) for a pending checkout acceptance referencing the poisoned record and opens the resulting CSV in Excel, LibreOffice Calc, or Google Sheets, the injected content is evaluated as a formula in the downloader's spreadsheet context, enabling data exfiltration (e.g., HYPERLINK/WEBSERVICE) or, on legacy Windows Excel configurations, DDE command execution. Fixed in 8.7.0.
Title Snipe-IT before 8.7.0 CSV Formula Injection via Asset Acceptance Report
First Time appeared Snipeitapp
Snipeitapp snipe-it
Weaknesses CWE-1236
CPEs cpe:2.3:a:snipeitapp:snipe-it:*:*:*:*:*:*:*:*
Vendors & Products Snipeitapp
Snipeitapp snipe-it
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L'}


Subscriptions

Snipeitapp Snipe-it
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-10T14:57:52.573Z

Reserved: 2026-09-08T11:31:38.679Z

Link: CVE-2026-86742

cve-icon Vulnrichment

Updated: 2026-09-10T14:18:45.847Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T14:17:22.820

Modified: 2026-09-14T20:47:24.720

Link: CVE-2026-86742

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T17:45:16Z

Weaknesses
  • CWE-1236

    Improper Neutralization of Formula Elements in a CSV File