THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-xr9m-gphc-9p63 (low) — Snipe-IT has a path traversal vulnerability via CSV import `image` field

[GHSA] GHSA-xr9m-gphc-9p63 (low) — Snipe-IT has a path traversal vulnerability via CSV import `image` field

medgithub_advisoriesPublished 2026-08-28

GHSA-xr9m-gphc-9p63 Severity: low CVE: CVE-2026-55469

Snipe-IT has a path traversal vulnerability via CSV import `image` field

### Impact An authenticated user holding the `import` and `assets.update` permissions can delete arbitrary files on the server filesystem by injecting a path traversal string into an asset's `image` field via CSV import, then triggering the image deletion feature.

Indicators of compromise

Original source: https://github.com/advisories/GHSA-xr9m-gphc-9p63