← back
CVE-2026-55469mediumCWE-22

Snipe-IT: Path traversal vulnerability via CSV import `image` field

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 6.5epss 0.6%
exploitation probability
0.6%top 53% of all CVEs
observed exploitation
nono source reports it
Snipe-IT is an IT asset/license management system. Prior to 8.6.2, an authenticated user with import and assets.update permissions can place a path traversal string in an asset image field through CSV import and then trigger image deletion, allowing deletion of arbitrary files accessible to the server process. This issue is fixed in version 8.6.2.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
Affected products
grokability · snipe-it