Description
Snipe-IT is an IT asset management application. In Snipe-IT master-branch builds after 8.6.3 (the code was never included in a tagged release), SettingsController::downloadLocationScopingReport streams the FMCS location-scoping mismatch report (GET /admin/settings/location-scoping-report.csv) through a bare fputcsv() call without applying League\Csv\EscapeFormula, unlike the other CSV exports which honor config('app.escape_formulas'). An authenticated user with ordinary create/edit rights can place a spreadsheet formula in free-text fields that appear in the report (item name, asset tag, serial, item or location company name, location name) and arrange for the record to be FMCS-mismatched so it is included in the export. When a superuser downloads the report and opens it in Excel, LibreOffice Calc, or Google Sheets with formula evaluation enabled and external-content warnings dismissed or disabled, cells beginning with =, +, -, @, tab, or CR are executed in the victim's spreadsheet context, enabling data exfiltration (e.g., HYPERLINK/WEBSERVICE) or, on Windows Excel, legacy DDE command execution. This issue is fixed in version 8.7.0.
Published: 2026-09-09
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Spreadsheet formula injection enabling data exfiltration or legacy command execution
Action: Update to 8.7.0
AI Analysis

Impact

Snipe‑IT’s export routine bypasses formula escaping when generating a location‑scoping report. The unescaped output allows an attacker to embed spreadsheet formulas that begin with characters such as =, +, -, @, a tab, or a carriage return. When a superuser downloads the CSV and opens it in Excel, LibreOffice Calc, or Google Sheets with formula evaluation enabled, the embedded formulas execute in the client’s context, permitting data exfiltration via HYPERLINK/WEBSERVICE or, on Windows, execution of legacy DDE commands. The CVSS score of 5.1 indicates moderate severity, with a potential impact on confidentiality, integrity, and availability for the victim’s environment.

Affected Systems

The flaw exists in grokability's Snipe‑IT versions built on the master branch after 8.6.3 but before the release of version 8.7.0. Users with ordinary create or edit rights can inject malicious formulas into free‑text fields that appear in the report, while a superuser who downloads the export can trigger their execution. All deployments of the affected Snipe‑IT code, regardless of hosting environment, are vulnerable until updated to 8.7.0.

Risk and Exploitability

The vulnerability requires authenticated access; an attacker needs permission to modify assets or locations to place a formula into a field, and then a privileged user must download the CSV and open it with a client that evaluates formulas. The EPSS score is not provided, and the issue is not listed in CISA’s KEV catalog, suggesting limited publicly known exploitation activity. Nonetheless, the attack path is realistic and the potential for data loss or execution of arbitrary commands warrants swift remediation.

Generated by OpenCVE AI on September 9, 2026 at 16:08 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official update to Snipe‑IT version 8.7.0 or later, which restores proper CSV escaping for location‑scoping reports.
  • If an immediate upgrade is unavailable, enforce a policy that disables formula evaluation in any spreadsheet client that will open exported files, or instruct end‑users to enable the ‘disable external content’ setting before opening the CSV.
  • Restrict create/edit permissions to trusted personnel or remove the ability for untrusted users to add or edit fields that appear in location‑scoping reports, thereby preventing malicious formula injection.

Generated by OpenCVE AI on September 9, 2026 at 16:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:snipeitapp:snipe-it:8.6.3:*:*:*:*:*:*:*

Mon, 14 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Grokability
Grokability snipe-it
Vendors & Products Grokability
Grokability snipe-it

Wed, 09 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
Description Snipe-IT is an IT asset management application. In Snipe-IT master-branch builds after 8.6.3 (the code was never included in a tagged release), SettingsController::downloadLocationScopingReport streams the FMCS location-scoping mismatch report (GET /admin/settings/location-scoping-report.csv) through a bare fputcsv() call without applying League\Csv\EscapeFormula, unlike the other CSV exports which honor config('app.escape_formulas'). An authenticated user with ordinary create/edit rights can place a spreadsheet formula in free-text fields that appear in the report (item name, asset tag, serial, item or location company name, location name) and arrange for the record to be FMCS-mismatched so it is included in the export. When a superuser downloads the report and opens it in Excel, LibreOffice Calc, or Google Sheets with formula evaluation enabled and external-content warnings dismissed or disabled, cells beginning with =, +, -, @, tab, or CR are executed in the victim's spreadsheet context, enabling data exfiltration (e.g., HYPERLINK/WEBSERVICE) or, on Windows Excel, legacy DDE command execution. This issue is fixed in version 8.7.0.
Title Snipe-IT before 8.7.0 CSV Formula Injection via Location-Scoping Export
First Time appeared Snipeitapp
Snipeitapp snipe-it
Weaknesses CWE-1236
CPEs cpe:2.3:a:snipeitapp:snipe-it:*:*:*:*:*:*:*:*
Vendors & Products Snipeitapp
Snipeitapp snipe-it
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L'}


Subscriptions

Grokability Snipe-it
Snipeitapp Snipe-it
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-14T13:20:54.862Z

Reserved: 2026-09-08T11:31:38.679Z

Link: CVE-2026-86745

cve-icon Vulnrichment

Updated: 2026-09-14T13:20:49.112Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T14:17:23.277

Modified: 2026-09-14T20:38:00.663

Link: CVE-2026-86745

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T17:15:06Z

Weaknesses
  • CWE-1236

    Improper Neutralization of Formula Elements in a CSV File