Impact
Snipe‑IT’s export routine bypasses formula escaping when generating a location‑scoping report. The unescaped output allows an attacker to embed spreadsheet formulas that begin with characters such as =, +, -, @, a tab, or a carriage return. When a superuser downloads the CSV and opens it in Excel, LibreOffice Calc, or Google Sheets with formula evaluation enabled, the embedded formulas execute in the client’s context, permitting data exfiltration via HYPERLINK/WEBSERVICE or, on Windows, execution of legacy DDE commands. The CVSS score of 5.1 indicates moderate severity, with a potential impact on confidentiality, integrity, and availability for the victim’s environment.
Affected Systems
The flaw exists in grokability's Snipe‑IT versions built on the master branch after 8.6.3 but before the release of version 8.7.0. Users with ordinary create or edit rights can inject malicious formulas into free‑text fields that appear in the report, while a superuser who downloads the export can trigger their execution. All deployments of the affected Snipe‑IT code, regardless of hosting environment, are vulnerable until updated to 8.7.0.
Risk and Exploitability
The vulnerability requires authenticated access; an attacker needs permission to modify assets or locations to place a formula into a field, and then a privileged user must download the CSV and open it with a client that evaluates formulas. The EPSS score is not provided, and the issue is not listed in CISA’s KEV catalog, suggesting limited publicly known exploitation activity. Nonetheless, the attack path is realistic and the potential for data loss or execution of arbitrary commands warrants swift remediation.
OpenCVE Enrichment