CVE-2025-63601: Malicious File Upload
Published Nov 5, 2025
·Updated
Snipe-IT before version 8.3.3 contains a remote code execution vulnerability that allows an authenticated attacker to upload a malicious backup file containing arbitrary files and execute system commands.
Affected Software
2 affected components
Snipe-IT Snipe-IT<8.3.3
Snipeitapp Snipe-it<8.3.3
Remediation
Patch Available
Event History
Nov 5, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-63601?
CVE-2025-63601 is classified as a critical remote code execution vulnerability.
2
How do I fix CVE-2025-63601?
To resolve CVE-2025-63601, update Snipe-IT to version 8.3.3 or later.
3
Who is affected by CVE-2025-63601?
CVE-2025-63601 affects all versions of Snipe-IT prior to version 8.3.3.
4
What actions can an attacker perform using CVE-2025-63601?
An authenticated attacker can exploit CVE-2025-63601 to upload malicious files and execute system commands.
5
When was CVE-2025-63601 identified?
CVE-2025-63601 was identified with a disclosure date in 2025.