Executive brief
Snipe-IT, an open-source IT asset management system, is vulnerable to a security flaw where malicious scripts can be stored in component checkout notes. If an attacker with basic user access saves a specially crafted note, the script could execute in the browser of other users who view that component. This could lead to unauthorized actions being performed on behalf of other users or the theft of sensitive session information.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in Snipe-IT versions prior to 8.4.1. The root cause is the failure to escape user-supplied input in the 'notes' column when viewing component checkout details. An attacker with low-level privileges (component view/edit access) can inject malicious JavaScript into the notes field. This script is then executed in the context of any user who views the affected component page. The vulnerability is tracked as CVE-2026-44831 and was addressed by ensuring proper output encoding in the affected view.
Affected products
- Grokability Snipe-IT < 8.4.1
Timeline
- 2026-05-05: patched: Fix committed to repository
- 2026-05-08: advisory: GitHub Advisory published
- 2026-05-26: other: NVD published date
References
- https://api.github.com/users/lorenzofradeani
- https://github.com/lorenzofradeani
- https://api.github.com/users/lorenzofradeani/gists%7B/gist_id%7D
- https://api.github.com/users/lorenzofradeani/repos
- https://avatars.githubusercontent.com/u/188067212?v=4
- https://api.github.com/users/lorenzofradeani/events%7B/privacy%7D