Snipe-IT is an IT asset/license management system. Prior to 8.5.0, ActionlogController::displaySig concatenates the route filename parameter into a private upload-directory path without sanitization, allowing an authenticated attacker to traverse outside the intended directory and read arbitrary files accessible to the web server process. This issue is fixed in version 8.5.0.
References
| Link | Resource |
|---|---|
| https://github.com/grokability/snipe-it/commit/cd69a7ea53e030e6e05f08be18daac672c8c4121 | Patch |
| https://github.com/grokability/snipe-it/pull/18927 | Issue Tracking Patch |
| https://github.com/grokability/snipe-it/releases/tag/v8.5.0 | Release Notes |
| https://github.com/grokability/snipe-it/security/advisories/GHSA-c6f4-wj38-m3g3 | Patch Vendor Advisory |
Configurations
History
10 Jul 2026, 20:16
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/grokability/snipe-it/commit/cd69a7ea53e030e6e05f08be18daac672c8c4121 - Patch | |
| References | () https://github.com/grokability/snipe-it/pull/18927 - Issue Tracking, Patch | |
| References | () https://github.com/grokability/snipe-it/releases/tag/v8.5.0 - Release Notes | |
| References | () https://github.com/grokability/snipe-it/security/advisories/GHSA-c6f4-wj38-m3g3 - Patch, Vendor Advisory | |
| CPE | cpe:2.3:a:snipeitapp:snipe-it:*:*:*:*:*:*:*:* | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.5 |
| First Time |
Snipeitapp
Snipeitapp snipe-it |
10 Jul 2026, 19:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-10 19:17
Updated : 2026-07-10 20:16
NVD link : CVE-2026-55474
Mitre link : CVE-2026-55474
CVE.ORG link : CVE-2026-55474
JSON object : View
Products Affected
snipeitapp
- snipe-it
CWE
CWE-23
Relative Path Traversal
