Junglewise Threat Intelligence

CVE-2026-55461: Grokability Snipe-IT open redirect in user edit flow

CVE-2026-55461 · Severity: medium · CVSS 6.1 · Published 2026-07-10

Technologies: Snipe IT Snipe-It, snipe/snipe-it (Packagist). Vendors: Packagist.

Executive brief

Snipe-IT is an asset management platform used to track IT equipment and inventory. An authenticated user with permission to edit user records can be redirected to an attacker-controlled external website after completing a normal user-edit action. An attacker can exploit this by sending a logged-in user a malicious link to the user-edit page, causing them to be redirected to a phishing site or other malicious destination after saving their changes, potentially compromising user credentials or trust in the application.

Technical details

This is an open redirect vulnerability (CWE-601) in Snipe-IT's user edit flow. The vulnerable code stores the attacker-controlled Referer HTTP header into Laravel's session-based intended URL using `url()->previous()`, then later redirects to that stored URL when the user submits the form with `redirect_option=back` via `redirect()->intended(...)`. Because the Referer header is derived from user input, an attacker can craft a URL with a malicious Referer header pointing to an external site. An authenticated user with user-edit permissions is the target. When such a user completes a legitimate user edit action, they are transparently redirected to the attacker-controlled destination, which can be used for phishing or social engineering attacks. The vulnerability was patched in version 8.6.2 (commit f4cac96358). Affected versions are Snipe-IT 8.6.1 and earlier.

Affected products

  • Snipe IT Snipe-IT <= 8.6.1

Timeline

  • 2026-06-24: disclosed: Published in GitHub Advisory Database (initial advisory date)
  • 2026-08-28: advisory: Updated in GitHub Advisory Database
  • 2026-06-24: patched: Patched in version 8.6.2 (commit f4cac96358)

References

Related threats