Junglewise Threat Intelligence

CVE-2025-65621: Snipe-IT stored XSS in Accessory Checkout Notes field

CVE-2025-65621 · Severity: medium · CVSS 5.4 · Published 2025-12-01

Technologies: Snipe-It, snipe/snipe-it (Packagist). Vendors: Snipeitapp, Packagist.

Executive brief

Snipe-IT is an open-source asset management system used by organizations to track hardware and software. A security flaw allows a low-privileged user to inject malicious code into the 'Notes' field when checking out an accessory. If an administrator views the affected user's profile, this code executes in their browser, potentially allowing the attacker to take over the administrator's account or perform unauthorized actions.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in Snipe-IT versions prior to 8.3.4 due to improper neutralization of input in the Accessory Checkout 'Notes' field. An authenticated attacker with low-level accessory management permissions can inject a malicious JavaScript payload into this field. The payload is stored and subsequently executed in the context of a higher-privileged user (such as an administrator) when they visit the specific user profile page (/user/{userId}) associated with the checkout. This can lead to session hijacking and privilege escalation. The issue is addressed in version 8.3.4.

Affected products

  • Snipe-IT Snipe-IT before 8.3.4

Timeline

  • 2025-10-14: disclosed: Vulnerability discovered and vendor notified
  • 2025-10-17: patched: Patch released in version 8.3.4
  • 2025-12-01: advisory: NVD publication date

References

Related threats