THREAT OPS › Threat News › [GHSA] GHSA-wg2f-x2c2-c4rp (medium) — Snipe-IT has an Open Redirect After User Edit
[GHSA] GHSA-wg2f-x2c2-c4rp (medium) — Snipe-IT has an Open Redirect After User Edit
GHSA-wg2f-x2c2-c4rp Severity: medium CVE: CVE-2026-55461
Snipe-IT has an Open Redirect After User Edit
### Impact The user edit flow stores `url()->previous()` into Laravel's intended URL session value and later redirects with `redirect()->intended(...)` when `redirect_option=back` is submitted. Because the previous URL is derived from the attacker-controlled `Referer` header, an authenticated u
Indicators of compromise
- CVE-2026-55461cve
Original source: https://github.com/advisories/GHSA-wg2f-x2c2-c4rp