Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
🐘
🐘 Packagist
Not in CISA KEV
MEDIUM severity

Incorrect Default Permissions and Improper Access Control in snipe-itGHSA-w3v3-cxq5-9vr4

MEDIUMFix: snipe/snipe-it#10498

GHSA-w3v3-cxq5-9vr4 is a medium-severity (CVSS 5.4) CWE-862 vulnerability in snipe/snipe-it. 1 public exploit reference exists, so weaponization risk is real. A fix is available for snipe/snipe-it — see the affected versions and patch details below.

Also known asCVE-2022-0179
Published
Updated
Affected
1 pkg
Patched
1 / 1
Exploits
1 known
Exploitation data as of Oct 11, 2026 · OSV.dev, NVD, FIRST.org (EPSS)

EPSS Exploitation Probability

via FIRST.org ↗
0.6%probability of exploitation in next 30 days
Lower Risk0.00%
Lower risk than most CVEs49th percentile — riskier than 49% of all scored CVEsHighest risk
0.00%0.38%0.76%1.14%0.2%0.6%Apr 26Aug 26Oct 26

Probability of exploitation in the next 30 days, from FIRST.org EPSS.

How urgent is this, really

GHSA-w3v3-cxq5-9vr4 by exploitation likelihood (EPSS) against impact (CVSS). Outside the shaded patch-first corner.

Where this sits among everything scored

Of 385,386 CVEs with a current EPSS score, this one falls in the < 10% band (highlighted). Counts from FIRST.org, log-scaled.

Real-World Exposure

1 pkg affected
🐘snipe/snipe-it

Real-time download stats are indexed for npm and PyPI packages. This vulnerability affects Packagist packages — download data is not available via public APIs for these ecosystems.

Description

snipe-it is vulnerable to Improper Access Control/Incorrect Default Permissions.

Affected Packages

1 total 1 fixed
EcosystemPackageVulnerable rangeFix
🐘Packagistsnipe/snipe-itall versions5.3.7composer require snipe/snipe-it:^5.3.7

Affected Products

1 product · 1 configurations
Application
snipe-itsnipeitapp
< 5.3.7
range
Exploits & PoCs
1

Research use only. For defensive security, authorized penetration testing, and academic research only. Never execute exploit code against systems without explicit written authorization.

Detection & mitigation playbook

Open-source dependency
  1. Detect

    Scan your dependency tree (package-lock.json, pnpm-lock.yaml, requirements.txt, go.sum, etc.) for snipe/snipe-it, including transitive dependencies — a direct dependency you never call can still pull in a vulnerable version.

  2. Fix

    Update snipe/snipe-it to 5.3.7 or later, then make sure no transitive (indirect) dependency still pins the vulnerable range — O3 confirms GHSA-w3v3-cxq5-9vr4 is resolved across your whole dependency graph.

  3. Workarounds

    Close the privilege gap rather than the entry point: audit which accounts, roles and service identities can reach the affected operation, drop the component to the least privilege it actually needs, and review file and directory permissions created by earlier installs — a default left in place is what makes this reachable.

Frequently Asked Questions

snipe-it is vulnerable to Improper Access Control/Incorrect Default Permissions.
O3 Security · Impact-Aware SCA

Is GHSA-w3v3-cxq5-9vr4 in your dependencies?

Find it across Packagist, including transitive dependencies.

Incorrect Default Permissions and Improper Access…