{"id":"CVE-2026-61807","aliases":["GHSA-c8qc-wf67-342w"],"url":"https://o3.security/vulnerability/CVE-2026-61807","summary":"Snipe-IT: Stored DOM XSS via table selected-count IDs","details":"### Impact\nThe table component derives data-selected-count-id from the component $name value. On manufacturer and supplier detail pages, stored manufacturer or supplier names are passed into affected table components as that name value. The client-side JavaScript later reads the browser-decoded data-selected-count-id, uses it as a selector, and concatenates countId.substring(1) directly into an HTML string passed to jQuery .after().\n\nAffected commit:\n\n`b224cc636c6780386e3f73f03d1171f52ab4c37a`\n\nExample payload for a manufacturer or supplier name:\n`x[foo=\"><svg/onload=alert(1)>\"]>`\n\nThe issue appears to involve the following flow:\n\nStored supplier/manufacturer name\n-> table component data-selected-count-id\n-> browser decodes the attribute\n-> JavaScript reads countId\n-> countId is used as a selector\n-> countId.substring(1) is concatenated into HTML\n-> jQuery .after() inserts attacker-controlled markup\n-> JavaScript executes in the victim's browser\n\nPotential impact includes arbitrary JavaScript execution in the browser of an authenticated Snipe-IT user who views the affected supplier or manufacturer detail page. If the victim has elevated privileges, this may allow access to data or actions available to that user's session.\n\n### Patches\nPatched in https://github.com/grokability/snipe-it/commit/d12ad3d53869443b96b663ba3ce2673ef343da71","published":"2026-08-19T18:22:21.559Z","modified":"2026-10-02T03:47:30.823986098Z","cvss":null,"epss":{"score":0.00284,"percentile":0.20366,"asOf":"2026-08-24"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"snipe/snipe-it","fixedVersion":"8.6.2"}],"fix":{"url":"https://github.com/grokability/snipe-it/commit/d12ad3d53869443b96b663ba3ce2673ef343da71","label":"grokability/snipe-it@d12ad3d"},"references":[{"type":"WEB","url":"https://github.com/grokability/snipe-it/releases/tag/v8.6.2"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/61xxx/CVE-2026-61807.json"},{"type":"ADVISORY","url":"https://github.com/grokability/snipe-it/security/advisories/GHSA-c8qc-wf67-342w"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-61807"},{"type":"FIX","url":"https://github.com/grokability/snipe-it/commit/d12ad3d53869443b96b663ba3ce2673ef343da71"},{"type":"PACKAGE","url":"https://github.com/grokability/snipe-it"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-10-02T03:47:30.823986098Z"}}