Description
Snipe-IT versions before 8.7.0 fail to HTML-escape the employee_num field in the acceptance PDF generator, allowing attackers with users.edit permission to inject img tags into TCPDF's writeHTML() function. Attackers can craft a malicious employee_num value containing an img tag with an arbitrary HTTP(S) URL to trigger server-side requests to internal services, cloud metadata endpoints, or external targets when a victim signs an asset acceptance.
Published: 2026-09-09
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: Server-Side Request Forgery
Action: Immediate Patch
AI Analysis

Impact

Snipe-IT versions prior to 8.7.0 do not HTML-escape the employee_num field when generating acceptance PDFs, allowing attackers with users.edit permission to inject arbitrary <img> tags into TCPDF's writeHTML() function; the embedded image URL causes the server to issue a request to that address, resulting in server‑side request forgery. This flaw enables attackers to direct the application to connect to internal network services, cloud metadata endpoints, or external targets, potentially exposing sensitive data or facilitating further lateral movement. The impact is primarily a confidentiality breach through internal request redirection, with limited availability effects and no direct code execution.

Affected Systems

The affected product is Snipe‑IT, provided by Grokability. All releases before 8.7.0 are vulnerable, regardless of the operating system or deployment environment.

Risk and Exploitability

The vulnerability carries a CVSS score of 8.3, indicating high severity. No EPSS score is available, and the flaw is not listed in the CISA KEV catalog, but its exploitation requires only user-level edit rights and the ability to trigger asset acceptance, both of which are common administrative tasks. Attackers can exploit the flaw by injecting a crafted employee_num value containing an <img> tag with an arbitrary HTTP(S) URL, resulting in the Snipe‑IT server making unauthorized outbound requests. Because the vulnerability leverages existing PDF rendering code, it can be abused with minimal effort once the edit permission context is obtained.

Generated by OpenCVE AI on September 9, 2026 at 15:32 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Snipe‑IT to version 8.7.0 or later, which applies proper HTML escaping to the employee_num field.
  • Limit or remove the users.edit permission for accounts that do not require it, or isolate the PDF generation service on a network that blocks outbound HTTP requests to untrusted destinations.
  • Implement input validation or a content‑security policy that strips <img> tags from the employee_num field before it is passed to TCPDF, or temporarily disable the asset acceptance PDF feature until a patch is available.

Generated by OpenCVE AI on September 9, 2026 at 15:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Grokability
Grokability snipe-it
Vendors & Products Grokability
Grokability snipe-it

Wed, 09 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
Description Snipe-IT versions before 8.7.0 fail to HTML-escape the employee_num field in the acceptance PDF generator, allowing attackers with users.edit permission to inject img tags into TCPDF's writeHTML() function. Attackers can craft a malicious employee_num value containing an img tag with an arbitrary HTTP(S) URL to trigger server-side requests to internal services, cloud metadata endpoints, or external targets when a victim signs an asset acceptance.
Title Snipe-IT before 8.7.0 Server-Side Request Forgery via employee_num
First Time appeared Snipeitapp
Snipeitapp snipe-it
Weaknesses CWE-918
CPEs cpe:2.3:a:snipeitapp:snipe-it:*:*:*:*:*:*:*:*
Vendors & Products Snipeitapp
Snipeitapp snipe-it
References
Metrics cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:L'}

cvssV4_0

{'score': 8.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:N/VA:L/SC:H/SI:N/SA:L'}


Subscriptions

Grokability Snipe-it
Snipeitapp Snipe-it
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-09T14:06:59.808Z

Reserved: 2026-09-08T11:35:02.617Z

Link: CVE-2026-86771

cve-icon Vulnrichment

Updated: 2026-09-09T14:06:55.195Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T14:17:27.740

Modified: 2026-09-16T20:28:50.710

Link: CVE-2026-86771

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T15:30:06Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)