A AegiFlow
MEDIUMCVSS 4.8EPSS 0.2%

CVE-2026-55452

Snipe-IT has CSV formula injection in Activity Report export

Published
2026-08-28
Modified
2026-08-28
EPSS percentile
14%
Aliases
GHSA-whrx-mmgr-gpcf
Sources
github-advisory

Summary

### Impact In Snipe-IT v8.6.1 and lower, `Actionlog::logaction()` stores the request User-Agent header in user_agent. That value is later included in the Activity Report CSV export by `ReportsController::postActivityReport()` and written with plain `fputcsv()`. A low-privileged authenticated user can set a formula-like User-Agent, perform a logged action, and have that value stored in the activity log. If an admin or report viewer later exports the Activity Report and opens it in spreadsheet software, the formula may execute. Example payload: `User-Agent: =HYPERLINK("https://example.com/","click")`

Affected packages

EcosystemPackageAffected versionsFixed versions
Packagistsnipe/snipe-it8.6.2

Remediation: Upgrade to 8.6.2 or later.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.

EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.