Executive brief
Snipe-IT is an IT asset management platform used to track and organize company hardware assets. A low-privilege user can embed spreadsheet formulas (like =HYPERLINK) in asset names, serial numbers, and location fields. When a superuser exports the location-scoping report and opens it in Excel, LibreOffice, or Google Sheets, these formulas execute automatically, allowing attackers to exfiltrate sensitive data or run arbitrary commands on the administrator's workstation.
Technical details
The vulnerability is a CSV formula injection (CWE-1236) in the SettingsController::downloadLocationScopingReport method, which exports an FMCS location-scoping mismatch report via a bare fputcsv() call without escaping formula prefixes (=, +, -, @, tab, CR). An authenticated attacker with ordinary create/edit rights on assets, locations, or companies can inject formulas into free-text fields (item name, asset tag, serial, company name, location name) and arrange for records to be FMCS-mismatched so they appear in the export. When a superuser downloads and opens the CSV in a formula-evaluating spreadsheet application with formula evaluation enabled and external-content warnings disabled, the formulas execute in the superuser's context, enabling data exfiltration via HYPERLINK/WEBSERVICE or, on Windows Excel, legacy DDE command execution. The rest of Snipe-IT's CSV exports already implement League\Csv\EscapeFormula; this one was added to master after version 8.6.3 without the same protection. The vulnerability is fixed in version 8.7.0.
Affected products
- Snipe-IT Snipe-IT > 8.6.3 (master-branch builds, not in tagged release) fixed in 8.7.0
Timeline
- 2026-09-09: disclosed
- 2026-08-24: patched: Fix available in version 8.7.0