{"id":"CVE-2026-62368","aliases":["GHSA-p9h3-gvpq-5539"],"url":"https://o3.security/vulnerability/CVE-2026-62368","summary":"Snipe-IT: Stored XSS via Custom Field name in asset-list column headers","details":"### Impact\nA user with the \"customfields.create\" permission can store HTML/JS in a Custom Field name, which is later rendered as an asset-list column title WITHOUT escaping at app/Presenters/AssetPresenter.php line 364 ('title' => $field->name) and injected into the table header by the bundled bootstrap-table plugin. It executes for anyone who opens an asset list (e.g. /hardware), including superusers, on page load with no interaction. Since \"customfields.create\" can be granted to non-superusers, a lower-privileged user gets script execution in a superuser's session -> privilege escalation.\n\nSTEPS TO REPRODUCE\n1. As a user with \"customfields.create\", create a Custom Field named: `<img src=x onerror=alert(1)>`\n2. Add the field to a fieldset that is associated with an asset model.\n3. Open `/hardware` -> the payload executes on load.\n\nDEMONSTRATED IMPACT\nAn account holding ONLY \"customfields.create\" (HTTP 403 on /users) planted a payload that, when a superuser opened /hardware, issued an authenticated request in that session and granted the attacker's own account the \"superuser\" permission (afterwards: GET /users = 200, isSuperUser() = true).\n\nROOT CAUSE\n- Blade {{ }} encodes the data-columns attribute, but the browser decodes it back before bootstrap-table reads the title; bootstrap-table then renders the header title unescaped because its table-level \"escape\" option defaults to false and is never enabled. (The per-column 'escape' => true covers cell values, not the header title.)\n### Patches\nPatched in https://github.com/grokability/snipe-it/commit/58754e4e3b86b58a0c4523012ef04a2ae990d2c8","published":"2026-09-24T16:40:34.110Z","modified":"2026-09-27T03:30:44.278074268Z","cvss":{"score":8.1,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"Packagist","name":"snipe/snipe-it","fixedVersion":"8.7.0"}],"fix":{"url":"https://github.com/grokability/snipe-it/commit/58754e4e3b86b58a0c4523012ef04a2ae990d2c8","label":"grokability/snipe-it@58754e4"},"references":[{"type":"WEB","url":"https://github.com/grokability/snipe-it/releases/tag/v8.7.0"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/62xxx/CVE-2026-62368.json"},{"type":"ADVISORY","url":"https://github.com/grokability/snipe-it/security/advisories/GHSA-p9h3-gvpq-5539"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-62368"},{"type":"FIX","url":"https://github.com/grokability/snipe-it/commit/58754e4e3b86b58a0c4523012ef04a2ae990d2c8"},{"type":"PACKAGE","url":"https://github.com/grokability/snipe-it"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-27T03:30:44.278074268Z"}}