CVE-2026-55464
Snipe-IT vulnerable to stored XSS via Markdown custom field
Summary
### Impact CommonMark is configured with `html_input => 'escape'`, which blocks raw HTML injection. However, javascript: URIs in Markdown hyperlinks are not sanitized. A user with `assets.edit` permission can inject a malicious link into any markdown-textarea custom field. Any user who opens the asset detail page and clicks the link executes arbitrary JavaScript in their browser session.
Affected packages
| Ecosystem | Package | Affected versions | Fixed versions |
|---|---|---|---|
| Packagist | snipe/snipe-it | — | 8.6.2 |
Remediation: Upgrade to 8.6.2 or later.
References
Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.
CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.
EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.