Executive brief
Snipe-IT is an open-source asset management system used by organizations to track IT equipment and inventory. An authenticated user with asset editing permissions can inject malicious JavaScript links into markdown-formatted custom fields. When other users view an asset and click the injected link, arbitrary JavaScript executes in their browser session, potentially allowing credential theft, session hijacking, or data exfiltration.
Technical details
This is a stored cross-site scripting (XSS) vulnerability in the Markdown rendering pipeline of Snipe-IT. The CommonMark parser is configured with `html_input => 'escape'` which prevents raw HTML injection; however, this configuration does not sanitize `javascript:` URIs in Markdown hyperlinks. An attacker with `assets.edit` permission can craft a malicious Markdown link (e.g., `[click me](javascript:alert('xss'))`) in any markdown-textarea custom field. The payload is stored in the database and executed client-side when any user views the asset detail page and clicks the link. No special attack vector or user privileges are required beyond asset editing capability. The vulnerability was patched in version 8.6.2; affected versions include 8.6.1 and earlier.
Affected products
- grokability snipe-it <= 8.6.1
Timeline
- 2026-06-24: disclosed
- 2026-06-24: patched: Version 8.6.2 released
- 2026-08-28: advisory