THREAT OPS › Threat News › [GHSA] GHSA-jhph-5q74-pmfx (medium) — Snipe-IT vulnerable to stored XSS via inline-served attachment
[GHSA] GHSA-jhph-5q74-pmfx (medium) — Snipe-IT vulnerable to stored XSS via inline-served attachment
GHSA-jhph-5q74-pmfx Severity: medium CVE: CVE-2026-55466
Snipe-IT vulnerable to stored XSS via inline-served attachment
### Impact A low-privilege user can store an active-content payload as an asset attachment and have it served inline, same-origin, with an active Content-Type, achieving stored XSS. The application sanitizes uploads only when PHP finfo detects image/svg+xml. By submitting an XH
Indicators of compromise
- CVE-2026-55466cve
Original source: https://github.com/advisories/GHSA-jhph-5q74-pmfx