THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-r52f-r9v5-66xr (medium) — Snipe-IT vulnerable to stored XSS via Markdown custom field

[GHSA] GHSA-r52f-r9v5-66xr (medium) — Snipe-IT vulnerable to stored XSS via Markdown custom field

medgithub_advisoriesPublished 2026-08-28

GHSA-r52f-r9v5-66xr Severity: medium CVE: CVE-2026-55464

Snipe-IT vulnerable to stored XSS via Markdown custom field

### Impact CommonMark is configured with `html_input => 'escape'`, which blocks raw HTML injection. However, javascript: URIs in Markdown hyperlinks are not sanitized. A user with `assets.edit` permission can inject a malicious link into any markdown-textarea custom field. Any us

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-r52f-r9v5-66xr