THREAT OPS › Threat News › [GHSA] GHSA-whrx-mmgr-gpcf (medium) — Snipe-IT has CSV formula injection in Activity Report export
[GHSA] GHSA-whrx-mmgr-gpcf (medium) — Snipe-IT has CSV formula injection in Activity Report export
GHSA-whrx-mmgr-gpcf Severity: medium CVE: CVE-2026-55452
Snipe-IT has CSV formula injection in Activity Report export
### Impact In Snipe-IT v8.6.1 and lower, `Actionlog::logaction()` stores the request User-Agent header in user_agent. That value is later included in the Activity Report CSV export by `ReportsController::postActivityReport()` and written with plain `fputcsv()`.
A low-privileged
Indicators of compromise
- CVE-2026-55452cve
Original source: https://github.com/advisories/GHSA-whrx-mmgr-gpcf