THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-whrx-mmgr-gpcf (medium) — Snipe-IT has CSV formula injection in Activity Report export

[GHSA] GHSA-whrx-mmgr-gpcf (medium) — Snipe-IT has CSV formula injection in Activity Report export

medgithub_advisoriesPublished 2026-08-28

GHSA-whrx-mmgr-gpcf Severity: medium CVE: CVE-2026-55452

Snipe-IT has CSV formula injection in Activity Report export

### Impact In Snipe-IT v8.6.1 and lower, `Actionlog::logaction()` stores the request User-Agent header in user_agent. That value is later included in the Activity Report CSV export by `ReportsController::postActivityReport()` and written with plain `fputcsv()`.

A low-privileged

Indicators of compromise

Original source: https://github.com/advisories/GHSA-whrx-mmgr-gpcf