Executive brief
Snipe-IT is an open-source IT asset management platform used to track hardware, licenses, and inventory. The application fails to sanitize category EULA text before including it in checkout confirmation emails, allowing authenticated users with basic permissions to read arbitrary files from the server (including sensitive configuration files and credentials) and perform server-side request forgery attacks against internal systems.
Technical details
The vulnerability is an unsanitized input leading to arbitrary file read and SSRF in the mail rendering pipeline. The SnipeModel::getEula() method returns raw EULA text without sanitization, which is then passed to mail templates rendered as Markdown. The eduardokum/laravel-mail-auto-embed library walks the generated HTML and resolves all img tags server-side using file_get_contents() for local paths and curl for remote URLs (without certificate verification or private IP filtering), then inlines the response as MIME attachments. An authenticated attacker with basic IT clerk permissions (categories.create/edit, models.create, assets.create, assets.checkout) can inject markdown image syntax or HTML img tags pointing to local files (e.g., /var/www/html/.env containing database credentials and APP_KEY) or remote URLs, triggering exfiltration via the checkout confirmation email. The attack is non-blind: full file contents are returned as attachments. Patched in version 8.7.0; the fix registers BlockImagesMarkdownExtension on the mail CommonMark parser to neutralize markdown syntax while additionally sanitizing raw HTML img tags.
Affected products
- Grokability Snipe-IT before 8.7.0
Timeline
- 2026-08-24: disclosed: GitHub Security Advisory GHSA-qmhc-p47c-6x75 published
- 2026-09-09: advisory: NVD and public advisories published, CVE-2026-86741 assigned
- 2026-09-09: patched: Patch available in version 8.7.0