Impact
Authenticated users can submit markdown image syntax in checkout acceptance notes that is not properly sanitized. The CommonMark parser expands this syntax and laravel-mail-auto-embed resolves it by calling file_get_contents or curl, allowing the attacker to read arbitrary files on the server and issue server‑side HTTP requests. The vulnerability can expose sensitive files such as *.env, providing application keys and other credentials, or perform SSRF to internal resources. This constitutes a high‑severity data disclosure flaw with potential credential compromise.
Affected Systems
The flaw exists in the Snipe‑IT issue tracker, affecting all installations before version 8.7.0. The product is maintained by grokability and is identified by the CPEs cpe:2.3:a:snipeitapp:snipe-it:*:*:*:*:*:*:*:*.
Risk and Exploitability
With a CVSS score of 8.4 the vulnerability is considered high severity. EPSS information is not available, and the flaw is not listed in CISA KEV, but the absence of publicly disclosed exploits does not diminish the risk. The attack requires authenticated access with permission to add notes; once present, the attacker can trigger file reads or server‑side requests without further privileges. The potential for credential theft and internal reconnaissance means this vulnerability should be treated as a critical risk for affected deployments.
OpenCVE Enrichment