Back

HIGH

Snipe-IT before 8.7.0 Arbitrary File Read and SSRF via Markdown

Published Sep 9, 2026

Description

Snipe-IT before 8.7.0 fails to properly sanitize markdown image syntax in note fields, allowing authenticated users to read arbitrary server files and issue server-side HTTP requests. Attackers can submit markdown image syntax in checkout acceptance notes that survive HTML escaping, are expanded by CommonMark parser, and resolved by laravel-mail-auto-embed via file_get_contents or curl, exfiltrating sensitive files like .env containing APP_KEY.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Sep 9, 2026
Updated Sep 9, 2026
Reserved Sep 8, 2026
CISA Vulnrichment
Updated Sep 9, 2026
NVD
Status Analyzed
Modified Sep 14, 2026
Red Hat
Severity n/a
Public date n/a