Executive brief
Snipe-IT is an asset and inventory management system used by organizations to track consumable supplies like office equipment and materials. A race condition in the consumable checkout API allows authenticated users to simultaneously request the same items, causing both requests to succeed even when insufficient stock exists, resulting in negative inventory balances that corrupt stock records and undermine procurement workflows.
Technical details
A time-of-check-time-of-use (TOCTOU) race condition exists in the consumable checkout API endpoint (POST /api/v1/consumables/{consumable_id}/checkout). The vulnerability occurs because availability validation happens before the database transaction begins, and the transaction does not re-lock or re-validate the consumable row. An authenticated attacker with checkout permissions can submit concurrent requests for the same consumable; both requests observe the same inventory count, pass validation, and succeed, driving inventory negative. The fix (included in version 8.7.0) re-fetches the consumable row under a row-level lock (lockForUpdate) inside the transaction and re-validates availability before completing the checkout.
Affected products
- Snipe-IT Snipe-IT up to and including 8.6.3
Timeline
- 2026-08-24: disclosed
- 2026-07-25: patched: Fix released in version 8.7.0
- 2026-09-09: advisory