Snipe-IT, Stored DOM-Based Cross-Site Scripting (XSS), CVE-2026-61807 (Medium) -DC-Aug2026-1675

Listen to this Post

Snipe-IT is a popular open-source IT asset and license management system. Prior to version 8.6.2, a stored DOM-based Cross-Site Scripting (XSS) vulnerability existed in how the application handled manufacturer and supplier names. The root cause lies in the table component, which derives a `data-selected-count-id` attribute directly from the component’s `$name` value. On manufacturer and supplier detail pages, stored names are passed into this component.
The client-side JavaScript later reads this browser-decoded `data-selected-count-id` attribute. It uses this value as a selector and, critically, concatenates `countId.substring(1)` directly into an HTML string. This unsanitized string is then passed to the jQuery `.after()` function, which inserts it into the Document Object Model (DOM).
An attacker can exploit this by creating a malicious manufacturer or supplier name. For example, a name like `x[foo=”>“]>` can be used. When this name is stored and later viewed on the detail page, the injected payload is executed in the victim’s browser. The attack flow is: Stored supplier/manufacturer name → table component data-selected-count-id → browser decodes the attribute → JavaScript reads countId → countId is used as a selector → countId.substring(1) is concatenated into HTML → jQuery .after() inserts attacker-controlled markup → JavaScript executes in the victim’s browser.
The potential impact is the execution of arbitrary JavaScript in the browser of any authenticated Snipe-IT user viewing the affected page. If the victim has elevated privileges, this could lead to unauthorized data access or actions being performed on their behalf. The vulnerability is fixed in version 8.6.2, and the patch is available in the commit grokability/snipe-it@d12ad3d.

DailyCVE Form:

Platform: Snipe-IT
Version: <8.6.2
Vulnerability: Stored DOM XSS
Severity: Medium (CVSS 6.3)
date: 2026-08-19

Prediction: 2026-08-19 (Patched)

What Undercode Say:

Analytics:

To check if your Snipe-IT instance is vulnerable, verify the version.

Check the version of your Snipe-IT instance
php artisan snipe-it:version

To identify if a payload has been injected, search the database for the malicious pattern in manufacturer or supplier names.

Search for potential XSS payloads in the database (example using MySQL)
mysql -u [bash] -p[bash] [bash] -e "SELECT FROM manufacturers WHERE name LIKE '%<svg%' OR name LIKE '%onload%';"
mysql -u [bash] -p[bash] [bash] -e "SELECT FROM suppliers WHERE name LIKE '%<svg%' OR name LIKE '%onload%';"

Exploit: (Educational Purposes!)

An attacker can inject a payload by creating or updating a manufacturer or supplier with a crafted name. The following is a proof-of-concept payload that triggers an alert box.

x[foo="><svg/onload=alert(1)>"]>

When an administrator or any user views the detail page of this manufacturer or supplier, the JavaScript code `alert(1)` will execute in their browser.

Protection:

The primary protection is to update Snipe-IT to version 8.6.2 or later. The fix is included in commit grokability/snipe-it@d12ad3d. If an immediate update is not possible, you can implement a web application firewall (WAF) rule to block requests containing suspicious patterns like <svg, onload=, or similar XSS payloads in manufacturer and supplier name fields.

Impact:

Successful exploitation allows an attacker to execute arbitrary JavaScript code in the context of an authenticated user’s session. This can lead to:
– Data Theft: Stealing session cookies, API keys, or other sensitive information displayed on the page.
– Privilege Escalation: Performing actions on behalf of the victim user, potentially including administrative tasks if the victim is an admin.
– Account Takeover: Hijacking the user’s session.
– Defacement: Altering the content of the page as seen by the victim.

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top