THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-wg2f-x2c2-c4rp (medium) — Snipe-IT has an Open Redirect After User Edit

[GHSA] GHSA-wg2f-x2c2-c4rp (medium) — Snipe-IT has an Open Redirect After User Edit

medgithub_advisoriesPublished 2026-08-28

GHSA-wg2f-x2c2-c4rp Severity: medium CVE: CVE-2026-55461

Snipe-IT has an Open Redirect After User Edit

### Impact The user edit flow stores `url()->previous()` into Laravel's intended URL session value and later redirects with `redirect()->intended(...)` when `redirect_option=back` is submitted. Because the previous URL is derived from the attacker-controlled `Referer` header, an authenticated u

Indicators of compromise

Original source: https://github.com/advisories/GHSA-wg2f-x2c2-c4rp