Executive brief
Snipe-IT, an open-source IT asset management system, is vulnerable to an open redirect flaw. An attacker could trick a user into being redirected from the legitimate Snipe-IT domain to a malicious website. This could be used in phishing campaigns to steal user credentials or deliver malware, potentially damaging the organization's reputation and security posture.
Technical details
An open redirect vulnerability (CWE-601) exists in Snipe-IT due to insufficient validation of the HTTP Referer header when stored in a session variable. When a user performs a 'Save' action and the 'redirect_option' is set to 'back', the application retrieves the 'back_url' from the session via Helper::getRedirectOption() and executes a redirect to that URL. An attacker who can influence the session data (e.g., via session poisoning) can redirect users to arbitrary external domains. This vulnerability requires low privileges and user interaction, and is patched in version 8.4.1.
Affected products
- Grokability Snipe-IT < 8.4.1
Timeline
- 2026-05-05: disclosed
- 2026-05-08: advisory: GitHub Advisory published
- 2026-05-08: patched: Fix released in version 8.4.1