Description
Snipe-IT before 8.7.0 fails to properly sanitize markdown image syntax in note fields, allowing authenticated users to read arbitrary server files and issue server-side HTTP requests. Attackers can submit markdown image syntax in checkout acceptance notes that survive HTML escaping, are expanded by CommonMark parser, and resolved by laravel-mail-auto-embed via file_get_contents or curl, exfiltrating sensitive files like .env containing APP_KEY.
Published: 2026-09-09
Score: 8.4 High
EPSS: < 1% Very Low
KEV: No
Impact: Data Exfiltration / Sensitive File Disclosure
Action: Immediate Patch
AI Analysis

Impact

Authenticated users can submit markdown image syntax in checkout acceptance notes that is not properly sanitized. The CommonMark parser expands this syntax and laravel-mail-auto-embed resolves it by calling file_get_contents or curl, allowing the attacker to read arbitrary files on the server and issue server‑side HTTP requests. The vulnerability can expose sensitive files such as *.env, providing application keys and other credentials, or perform SSRF to internal resources. This constitutes a high‑severity data disclosure flaw with potential credential compromise.

Affected Systems

The flaw exists in the Snipe‑IT issue tracker, affecting all installations before version 8.7.0. The product is maintained by grokability and is identified by the CPEs cpe:2.3:a:snipeitapp:snipe-it:*:*:*:*:*:*:*:*.

Risk and Exploitability

With a CVSS score of 8.4 the vulnerability is considered high severity. EPSS information is not available, and the flaw is not listed in CISA KEV, but the absence of publicly disclosed exploits does not diminish the risk. The attack requires authenticated access with permission to add notes; once present, the attacker can trigger file reads or server‑side requests without further privileges. The potential for credential theft and internal reconnaissance means this vulnerability should be treated as a critical risk for affected deployments.

Generated by OpenCVE AI on September 9, 2026 at 15:43 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Snipe‑IT version 8.7.0 or later, which removes the vulnerable markdown handling
  • If upgrading is not immediately possible, disable markdown rendering in note fields or remove the laravel-mail-auto-embed package to block image resolution
  • Configure the application to restrict file_get_contents and curl to a whitelist of allowed directories and external hosts, and enforce strict file‑path validation to prevent arbitrary file access

Generated by OpenCVE AI on September 9, 2026 at 15:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 09 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
Description Snipe-IT before 8.7.0 fails to properly sanitize markdown image syntax in note fields, allowing authenticated users to read arbitrary server files and issue server-side HTTP requests. Attackers can submit markdown image syntax in checkout acceptance notes that survive HTML escaping, are expanded by CommonMark parser, and resolved by laravel-mail-auto-embed via file_get_contents or curl, exfiltrating sensitive files like .env containing APP_KEY.
Title Snipe-IT before 8.7.0 Arbitrary File Read and SSRF via Markdown
First Time appeared Snipeitapp
Snipeitapp snipe-it
Weaknesses CWE-73
CPEs cpe:2.3:a:snipeitapp:snipe-it:*:*:*:*:*:*:*:*
Vendors & Products Snipeitapp
Snipeitapp snipe-it
References
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N'}

cvssV4_0

{'score': 8.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N'}


Subscriptions

Snipeitapp Snipe-it
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-09T14:23:46.635Z

Reserved: 2026-09-08T11:32:11.095Z

Link: CVE-2026-86751

cve-icon Vulnrichment

Updated: 2026-09-09T14:23:22.507Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T14:17:24.170

Modified: 2026-09-14T20:29:41.480

Link: CVE-2026-86751

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T18:30:09Z

Weaknesses
  • CWE-73

    External Control of File Name or Path