CVE-2026-55452: Snipe-IT: CSV formula injection in Activity Report export
Snipe-IT is an IT asset/license management system. Prior to 8.5.0, Actionlog::logaction() stores the request User-Agent header and ReportsController::postActivityReport() writes that value to the Activity Report CSV without formula escaping, allowing a low-privileged authenticated user to store a formula-like User-Agent that may execute when a report viewer opens the exported CSV in spreadsheet software. This issue is fixed in version 8.5.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
snipe-itto a version that resolves this vulnerability.Fixed in 8.5.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-55452?
The severity of CVE-2026-55452 is medium, rated at 4.8 on the CVSS scale.
What is the impact of CVE-2026-55452?
CVE-2026-55452 allows a low-privileged authenticated user to inject malicious formulas into the Activity Report CSV export.
How do I fix CVE-2026-55452?
To fix CVE-2026-55452, upgrade to Snipe-IT version 8.5.0 or later, where the issue has been addressed.
Who is affected by CVE-2026-55452?
Users of Snipe-IT versions prior to 8.5.0 are affected by CVE-2026-55452.
What system does CVE-2026-55452 pertain to?
CVE-2026-55452 pertains to the Snipe-IT IT asset/license management system.