CVE-2026-61807: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in grokability snipe-it
CVE-2026-61807 is a stored cross-site scripting (XSS) vulnerability in the Snipe-IT IT asset/license management system. Versions prior to 8.6.2 improperly neutralize input when rendering manufacturer or supplier names, allowing crafted input to execute JavaScript in the context of authenticated users viewing certain detail pages. This can potentially expose data or enable actions available to the user's session. The issue is fixed in version 8.6.2.
AI Analysis
Technical Summary
Snipe-IT versions before 8.6.2 contain a stored XSS vulnerability due to improper neutralization of input in the table component where manufacturer or supplier names are used as data-selected-count-id attributes. Client-side code reads this attribute, decodes it, and uses it to build HTML passed to jQuery's .after() method. An attacker can craft a malicious name that executes JavaScript when an authenticated user views the affected pages. This vulnerability is tracked as CWE-79 and has a CVSS 4.0 score of 6.3 (medium severity).
Potential Impact
An attacker who can supply a malicious manufacturer or supplier name can execute arbitrary JavaScript in the browser of an authenticated user viewing the affected pages. This may lead to exposure of data or unauthorized actions within the user's session context. There is no indication of privilege escalation or remote code execution beyond the browser context.
Mitigation Recommendations
Upgrade Snipe-IT to version 8.6.2 or later, where this vulnerability is fixed. No other mitigation is indicated or required according to the available information.
CVE-2026-61807: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in grokability snipe-it
Description
CVE-2026-61807 is a stored cross-site scripting (XSS) vulnerability in the Snipe-IT IT asset/license management system. Versions prior to 8.6.2 improperly neutralize input when rendering manufacturer or supplier names, allowing crafted input to execute JavaScript in the context of authenticated users viewing certain detail pages. This can potentially expose data or enable actions available to the user's session. The issue is fixed in version 8.6.2.
CVSS v4.0
Score 6.3medium
Affected software
grokability
snipe-it
pkg:github/grokability/snipe-itRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Snipe-IT versions before 8.6.2 contain a stored XSS vulnerability due to improper neutralization of input in the table component where manufacturer or supplier names are used as data-selected-count-id attributes. Client-side code reads this attribute, decodes it, and uses it to build HTML passed to jQuery's .after() method. An attacker can craft a malicious name that executes JavaScript when an authenticated user views the affected pages. This vulnerability is tracked as CWE-79 and has a CVSS 4.0 score of 6.3 (medium severity).
Potential Impact
An attacker who can supply a malicious manufacturer or supplier name can execute arbitrary JavaScript in the browser of an authenticated user viewing the affected pages. This may lead to exposure of data or unauthorized actions within the user's session context. There is no indication of privilege escalation or remote code execution beyond the browser context.
Mitigation Recommendations
Upgrade Snipe-IT to version 8.6.2 or later, where this vulnerability is fixed. No other mitigation is indicated or required according to the available information.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-07-10T20:17:57.991Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6a85fb7bacd9273b497a3219
Added to database: 08/19/2026, 18:52:43 UTC
Last enriched: 09/11/2026, 07:49:53 UTC
Last updated: 10/02/2026, 02:46:05 UTC
Views: 78
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.