Junglewise Threat Intelligence

CVE-2026-55464: Grokability Snipe-IT stored XSS in Markdown custom fields

CVE-2026-55464 · Severity: medium · CVSS 5.4 · Published 2026-07-10

Technologies: Grokability Snipe-It, snipe/snipe-it (Packagist). Vendors: Packagist.

Executive brief

Snipe-IT is an open-source asset management system used by organizations to track IT equipment and inventory. An authenticated user with asset editing permissions can inject malicious JavaScript links into markdown-formatted custom fields. When other users view an asset and click the injected link, arbitrary JavaScript executes in their browser session, potentially allowing credential theft, session hijacking, or data exfiltration.

Technical details

This is a stored cross-site scripting (XSS) vulnerability in the Markdown rendering pipeline of Snipe-IT. The CommonMark parser is configured with `html_input => 'escape'` which prevents raw HTML injection; however, this configuration does not sanitize `javascript:` URIs in Markdown hyperlinks. An attacker with `assets.edit` permission can craft a malicious Markdown link (e.g., `[click me](javascript:alert('xss'))`) in any markdown-textarea custom field. The payload is stored in the database and executed client-side when any user views the asset detail page and clicks the link. No special attack vector or user privileges are required beyond asset editing capability. The vulnerability was patched in version 8.6.2; affected versions include 8.6.1 and earlier.

Affected products

  • grokability snipe-it <= 8.6.1

Timeline

  • 2026-06-24: disclosed
  • 2026-06-24: patched: Version 8.6.2 released
  • 2026-08-28: advisory

References

Related threats