CVE-2026-44831
medium
CVSS v3
5.4
CVSS v2
—
VIR risk
5.4
Description
Snipe-IT has Stored XSS via Component Checkout Notes (v8.4.0)
Predictions
Exploit likelihood
54%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: security-advisories@github.com — https://github.com/grokability/snipe-it/security/advisories/GHSA-r42m-953q-6vjx
Vendor advisory: security-advisories@github.com — https://github.com/grokability/snipe-it/security/advisories/GHSA-r42m-953q-6vjx
Vendor advisory: security-advisories@github.com — https://github.com/grokability/snipe-it/commit/28f493d84d057895fbb93b6570e7393a2c2fa438
Vendor advisory: security-advisories@github.com — https://github.com/grokability/snipe-it/commit/28f493d84d057895fbb93b6570e7393a2c2fa438
Package impact
| Ecosystem | Package | Vulnerable | Fixed |
|---|---|---|---|
| Packagist | snipe/snipe-it | <8.4.1 | 8.4.1 |
| COMPOSER | snipe/snipe-it | < 8.4.1 | 8.4.1 |
References
CWEs
CWE-79
Verify integrity in audit chain (admin only). AS-IS.