{"id":"CVE-2026-55452","aliases":["GHSA-whrx-mmgr-gpcf"],"url":"https://o3.security/vulnerability/CVE-2026-55452","summary":"Snipe-IT: CSV formula injection in Activity Report export","details":"Snipe-IT is an IT asset/license management system. Prior to 8.5.0, Actionlog::logaction() stores the request User-Agent header and ReportsController::postActivityReport() writes that value to the Activity Report CSV without formula escaping, allowing a low-privileged authenticated user to store a formula-like User-Agent that may execute when a report viewer opens the exported CSV in spreadsheet software. This issue is fixed in version 8.5.0.","published":"2026-07-10T19:40:05.790Z","modified":"2026-08-12T03:51:29.842965318Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[],"fix":{"url":"https://github.com/grokability/snipe-it/commit/7b7d2c87fbc965a7933b1bf9e3f2c331b8c8e19c","label":"grokability/snipe-it@7b7d2c8"},"references":[{"type":"WEB","url":"https://github.com/grokability/snipe-it/releases/tag/v8.5.0"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/55xxx/CVE-2026-55452.json"},{"type":"ADVISORY","url":"https://github.com/grokability/snipe-it/security/advisories/GHSA-whrx-mmgr-gpcf"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-55452"},{"type":"FIX","url":"https://github.com/grokability/snipe-it/commit/7b7d2c87fbc965a7933b1bf9e3f2c331b8c8e19c"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:29.842965318Z"}}