GHSA-wg2f-x2c2-c4rp: Medium severity composer/snipe/snipe-it vulnerability

Published Aug 28, 2026
·
Updated

Impact The user edit flow stores url()->previous() into Laravel's intended URL session value and later redirects with redirect()->intended(...) when redirectoption=back is submitted. Because the previous URL is derived from the attacker-controlled Referer header, an authenticated user performing a normal user-edit action can be redirected to an external attacker-controlled site.

An attacker who can cause a logged-in user with permission to edit a user record to open the edit page with an attacker-controlled Referer value.

The application can be used as a trusted redirector after a legitimate user edit action. This can support phishing or trust-boundary attacks against Snipe-IT users and matches a historical open redirect class where session-stored navigation context influences redirect destinations.

Patches Patched in f4cac96358

Affected Software

1 affected componentFixes available
composer/snipe/snipe-it<=8.6.1
8.6.2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade composer/snipe/snipe-it to a version that resolves this vulnerability.

    Fixed in 8.6.2
  2. Upgrade

    Upgrade Snipe-IT to a version that resolves this vulnerability.

    Patch f4cac96358

Event History

Aug 28, 2026
Advisory Published
via GitHub·05:57 PM
Data Sourced
via GitHub·05:57 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

Who is exposed to this redirect issue?

An attacker must target a logged-in user who has permission to edit a user record. The user must open the edit page with an attacker-controlled Referer value and then perform a normal user-edit action.

2

What configuration or workflow triggers the vulnerable redirect?

The affected path is used when the user-edit submission includes redirect_option=back. In that flow, the application stores the previous URL in the session and later redirects to it using the intended redirect mechanism.

3

What can an attacker do with this behavior?

The attacker can cause the application to redirect the authorized user to an external attacker-controlled site after the legitimate edit action. This can make the application act as a trusted redirector for phishing or trust-boundary attacks.

4

What patch information is available?

The issue is patched in commit f4cac96358.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203