A AegiFlow
MEDIUMCVSS 6.1EPSS 0.3%

CVE-2026-55461

Snipe-IT has an Open Redirect After User Edit

Published
2026-08-28
Modified
2026-08-28
EPSS percentile
23%
Aliases
GHSA-wg2f-x2c2-c4rp
Sources
github-advisory

Summary

### Impact The user edit flow stores `url()->previous()` into Laravel's intended URL session value and later redirects with `redirect()->intended(...)` when `redirect_option=back` is submitted. Because the previous URL is derived from the attacker-controlled `Referer` header, an authenticated user performing a normal user-edit action can be redirected to an external attacker-controlled site. An attacker who can cause a logged-in user with permission to edit a user record to open the edit page with an attacker-controlled `Referer` value. The application can be used as a trusted redirector after a legitimate user edit action. This can support phishing or trust-boundary attacks against Snipe-IT users and matches a historical open redirect class where session-stored navigation context influences redirect destinations. ### Patches Patched in f4cac96358

Affected packages

EcosystemPackageAffected versionsFixed versions
Packagistsnipe/snipe-it8.6.2

Remediation: Upgrade to 8.6.2 or later.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.

EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.