THREAT OPS › Threat News › [GHSA] GHSA-xr9m-gphc-9p63 (low) — Snipe-IT has a path traversal vulnerability via CSV import `image` field
[GHSA] GHSA-xr9m-gphc-9p63 (low) — Snipe-IT has a path traversal vulnerability via CSV import `image` field
GHSA-xr9m-gphc-9p63 Severity: low CVE: CVE-2026-55469
Snipe-IT has a path traversal vulnerability via CSV import `image` field
### Impact An authenticated user holding the `import` and `assets.update` permissions can delete arbitrary files on the server filesystem by injecting a path traversal string into an asset's `image` field via CSV import, then triggering the image deletion feature.
Indicators of compromise
- CVE-2026-55469cve
Original source: https://github.com/advisories/GHSA-xr9m-gphc-9p63