Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-62368— Snipe-IT: Stored XSS via Custom Field name in asset-list column headers

Quick assessment

Affected
grokability snipe-it
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Snipe-IT 是一款 IT 资产/许可证管理系统。在 8.7.0 版本之前,拥有 权限的用户可以将标记语言(markup)存储到 字段中,而 会将该值直接作为未转义的 Bootstrap-table 表头标题。当其他用户打开与该字段集关联的资产列表页面时,存储在 中的标记语言会在页面加载时于该用户的 Snipe-IT 会话中执行。这可能导致同源数据泄露,并允许攻击者以受害者的权限执行经身份验证的操作,包括当超级用户查看受影响的列表时实现权限提升。该问题已在 8.7.0 版本中修复。

CVSS 8.1 · High EPSS 0.30% · P21

Possible ATT&CK Techniques 1 AI

T1059 · Command and Scripting Interpreter

Affected Version Matrix 1

VendorProduct Version RangeStatus
grokability snipe-it < 8.7.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-62368

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Snipe-IT: Stored XSS via Custom Field name in asset-list column headers
Source: CVE Program / CVE List V5
Vulnerability Description
Snipe-IT is an IT asset/license management system. Prior to 8.7.0, a user with the customfields.create permission can store markup in CustomField.name, and app/Presenters/AssetPresenter.php assigns that value as an unescaped bootstrap-table header title. When another user opens an asset-list page associated with the fieldset, the stored markup executes on page load in that user's Snipe-IT session. This can expose same-origin data and perform authenticated actions with the victim's privileges, including privilege escalation when a superuser views the affected list. This issue is fixed in version 8.7.0.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
grokability snipe-it < 8.7.0 -

II. Public POCs for CVE-2026-62368

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-62368

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-62368 (1)

Vendor Advisories for CVE-2026-62368 (1)

Vendor Pages for CVE-2026-62368 (1)

Same Patch Batch · grokability · 2026-09-24 · 3 CVEs total

CVE-2026-63498 8.7 HIGH Snipe-IT: Stored XSS via Inline XML Rendering in the Uploaded Files API
CVE-2026-63493 8.6 HIGH Snipe-IT: 2FA bypass via the API token flow

IV. Related Vulnerabilities

V. Comments for CVE-2026-62368

No comments yet


Leave a comment