Executive brief
Snipe-IT is an open-source asset management system used to track and assign company equipment. A race condition in the asset checkout process allows two simultaneous checkout requests to both succeed for the same asset, resulting in duplicate audit log entries and incorrect utilization counters. While the asset's final assignment remains correct, the corrupted audit trail and statistics could mask inventory discrepancies during reconciliation.
Technical details
The vulnerability is a time-of-check time-of-use (TOCTOU) race condition in asset checkout paths: Api\AssetsController::checkout() and Assets\AssetCheckoutController::store() both call Asset::availableForCheckout() outside any database lock or transaction, then invoke Asset::checkOut() without re-validating availability or holding a row lock. Two concurrent requests for the same available asset both observe it as available and both execute the checkout, producing duplicate checkout-history rows, a doubled checkout_counter, and duplicate audit events. Exploitation requires an authenticated user with assets.checkout permission and precise concurrent timing on two HTTP requests targeting the same asset. The vulnerability was fixed in version 8.7.0 by wrapping the mutation path in a database transaction that acquires a row lock via lockForUpdate() and re-checks availability before proceeding.
Affected products
- Snipe-IT Snipe-IT 8.6.3 and earlier
Timeline
- 2026-08-24: disclosed
- 2026-07-25: patched: Fix committed; released in version 8.7.0
- 2026-09-09: advisory