Junglewise Threat Intelligence

CVE-2025-63743: Grokability Snipe-IT stored XSS in user profile fields

CVE-2025-63743 · Severity: medium · CVSS 5.4 · Published 2026-04-13

Technologies: Grokability Snipe-It.

Executive brief

Snipe-IT, a popular open-source IT asset management system, contains a security vulnerability that allows low-privileged users to inject malicious scripts into the system. By modifying their own profile names, an attacker can cause these scripts to run in the browsers of administrators or other staff members when they view activity reports or user lists. This could lead to unauthorized actions being performed on behalf of administrators or the theft of sensitive session information.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in Snipe-IT v8.3.0 and v8.3.1 due to improper output neutralization in the ActionlogsTransformer.php component. An authenticated attacker with minimal privileges can inject a JavaScript payload into the 'first_name' or 'last_name' fields during a profile update. The vulnerability is triggered if the 'Display Name' field is left unset, causing the application to fall back to the unsanitized name values. When an administrator or privileged user views the 'Activity Report' or the 'History' tab of the affected profile, the backend API returns unescaped code in the 'target' key, leading to script execution in the victim's browser. The issue was introduced in commit b6d397b and is fixed in version 8.3.2.

Affected products

  • Grokability Snipe-IT 8.3.0 to 8.3.1

Timeline

  • 2025-08-25: other: Vulnerability introduced in commit b6d397b
  • 2025-09-08: patched: Fixed in commit 2bee87298
  • 2026-04-12: disclosed: Vulnerability details published by researcher
  • 2026-04-13: advisory: CVE published to NVD

References