Executive brief
Snipe-IT is an asset management platform used to track IT equipment and inventory. An authenticated user with permission to edit user records can be redirected to an attacker-controlled external website after completing a normal user-edit action. An attacker can exploit this by sending a logged-in user a malicious link to the user-edit page, causing them to be redirected to a phishing site or other malicious destination after saving their changes, potentially compromising user credentials or trust in the application.
Technical details
This is an open redirect vulnerability (CWE-601) in Snipe-IT's user edit flow. The vulnerable code stores the attacker-controlled Referer HTTP header into Laravel's session-based intended URL using `url()->previous()`, then later redirects to that stored URL when the user submits the form with `redirect_option=back` via `redirect()->intended(...)`. Because the Referer header is derived from user input, an attacker can craft a URL with a malicious Referer header pointing to an external site. An authenticated user with user-edit permissions is the target. When such a user completes a legitimate user edit action, they are transparently redirected to the attacker-controlled destination, which can be used for phishing or social engineering attacks. The vulnerability was patched in version 8.6.2 (commit f4cac96358). Affected versions are Snipe-IT 8.6.1 and earlier.
Affected products
- Snipe IT Snipe-IT <= 8.6.1
Timeline
- 2026-06-24: disclosed: Published in GitHub Advisory Database (initial advisory date)
- 2026-08-28: advisory: Updated in GitHub Advisory Database
- 2026-06-24: patched: Patched in version 8.6.2 (commit f4cac96358)
References
- https://api.github.com/users/mamdouhmahfouz
- https://github.com/mamdouhmahfouz
- https://api.github.com/users/mamdouhmahfouz/gists%7B/gist_id%7D
- https://api.github.com/users/mamdouhmahfouz/repos
- https://avatars.githubusercontent.com/u/127619974?v=4
- https://api.github.com/users/mamdouhmahfouz/events%7B/privacy%7D