GHSA-r52f-r9v5-66xr: XSS

Published Aug 28, 2026
·
Updated

Impact CommonMark is configured with htmlinput => 'escape', which blocks raw HTML injection. However, javascript: URIs in Markdown hyperlinks are not sanitized. A user with assets.edit permission can inject a malicious link into any markdown-textarea custom field. Any user who opens the asset detail page and clicks the link executes arbitrary JavaScript in their browser session.

Affected Software

1 affected componentFixes available
composer/snipe/snipe-it<=8.6.1
8.6.2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade composer/snipe/snipe-it to a version that resolves this vulnerability.

    Fixed in 8.6.2
  2. Compensating control

    Restrict use of asset markdown-textarea custom fields (and/or the `assets.edit` permission) so only trusted users can create/edit content that could contain `javascript:` links.

Event History

Aug 28, 2026
Advisory Published
via GitHub·05:58 PM
Data Sourced
via GitHub·05:58 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

Who can exploit this issue?

An attacker needs an account with the assets.edit permission and access to a markdown-textarea custom field. They can place a malicious javascript: link in that field.

2

Who is affected after a malicious link has been added?

Any user who opens the affected asset detail page and clicks the malicious link can have arbitrary JavaScript execute in their browser session.

3

Does escaping raw HTML prevent exploitation?

No. The described CommonMark html_input => 'escape' configuration blocks raw HTML injection, but it does not sanitize javascript: URIs in Markdown hyperlinks.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203