<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 21:54:36 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-377660</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-377660</link>
      <description>EUVD-2026-377660</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-377660</guid>
    </item>
    <item>
      <title>fkie_cve-2026-63498</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-63498</link>
      <description>&lt;p&gt;Snipe-IT is an IT asset/license management system. Prior to 8.7.0, the uploaded-files API endpoint GET /api/v1/{object_type}/{id}/files/{file_id} allows an authenticated user with file-management access to upload XML and XSLT attachments and request them with the inline=true parameter. The app/Http/Controllers/Api/UploadedFilesController.php show() path does not apply the safe-inline allowlist used by the equivalent web controller, so the browser can process an attacker-controlled xml-stylesheet reference and execute JavaScript generated by the stylesheet in the Snipe-IT origin. A victim who is authorized to view the object must open the attachment URL, after which the script can read same-origin data and perform authenticated actions with the victim&amp;#39;s privileges. This issue is fixed in version 8.7.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Snipe-IT is an IT asset/license management system. Prior to 8.7.0, the uploaded-files API endpoint GET /api/v1/{object_type}/{id}/files/{file_id} allows an authenticated user with file-management access to upload XML and XSLT attachments and request them with the inline=true parameter. The app/Http/Controllers/Api/UploadedFilesController.php show() path does not apply the safe-inline allowlist used by the equivalent web controller, so the browser can process an attacker-controlled xml-stylesheet reference and execute JavaScript generated by the stylesheet in the Snipe-IT origin. A victim who is authorized to view the object must open the attachment URL, after which the script can read same-origin data and perform authenticated actions with the victim&amp;#39;s privileges. This issue is fixed in version 8.7.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-63498</guid>
    </item>
    <item>
      <title>GHSA-396x-xmvh-p563 — Snipe-IT: Stored XSS via Inline XML Rendering in the Uploaded Files API</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-396x-xmvh-p563</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: snipe/snipe-it&lt;/p&gt;
&lt;p&gt;Snipe-IT&amp;#39;s uploaded-files API accepts XML documents and later serves them inline without applying the safe-inline allowlist used by the equivalent web controller. An authenticated user who can attach files to a supported object can upload an XSLT stylesheet and an XML document that references it through xml-stylesheet. When another authorized user opens the XML file through the API with ?inline=true, the browser applies the attacker-controlled stylesheet, which produces HTML containing JavaScript in the Snipe-IT origin.
This was reproduced against commit df8e3b144331d0c1cc14778f900e7646d1d9a509 (v8.6.3-231-gdf8e3b1443).&lt;/p&gt;
&lt;p&gt;The attack requires an authenticated account with file access to at least one supported object and one victim interaction. Scope changes because attacker-controlled code executes in another user&amp;#39;s Snipe-IT security context. The script can read same-origin data available to the victim and perform authenticated actions as that victim.&lt;/p&gt;
&lt;p&gt;### Affected Components&lt;/p&gt;
&lt;p&gt;- app/Http/Requests/UploadFileRequest.php
Allows xml uploads through filesystems.allowed_upload_extensions_for_validator.
Sanitizes only files detected as image/svg+xml. Both files in this proof of concept are detected by PHP finfo as text/xml, so they are stored unchanged.
- config/filesystems.php
Includes xml in allowed_upload_extensions_array.
- app/Http/Controllers/Api/UploadedFilesController.php, method show()
Honors the attacker-controlled inline=true query parameter for every uploaded file type.
C…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: snipe/snipe-it&lt;/p&gt;
&lt;p&gt;Snipe-IT&amp;#39;s uploaded-files API accepts XML documents and later serves them inline without applying the safe-inline allowlist used by the equivalent web controller. An authenticated user who can attach files to a supported object can upload an XSLT stylesheet and an XML document that references it through xml-stylesheet. When another authorized user opens the XML file through the API with ?inline=true, the browser applies the attacker-controlled stylesheet, which produces HTML containing JavaScript in the Snipe-IT origin.
This was reproduced against commit df8e3b144331d0c1cc14778f900e7646d1d9a509 (v8.6.3-231-gdf8e3b1443).&lt;/p&gt;
&lt;p&gt;The attack requires an authenticated account with file access to at least one supported object and one victim interaction. Scope changes because attacker-controlled code executes in another user&amp;#39;s Snipe-IT security context. The script can read same-origin data available to the victim and perform authenticated actions as that victim.&lt;/p&gt;
&lt;p&gt;### Affected Components&lt;/p&gt;
&lt;p&gt;- app/Http/Requests/UploadFileRequest.php
Allows xml uploads through filesystems.allowed_upload_extensions_for_validator.
Sanitizes only files detected as image/svg+xml. Both files in this proof of concept are detected by PHP finfo as text/xml, so they are stored unchanged.
- config/filesystems.php
Includes xml in allowed_upload_extensions_array.
- app/Http/Controllers/Api/UploadedFilesController.php, method show()
Honors the attacker-controlled inline=true query parameter for every uploaded file type.
C…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-396x-xmvh-p563</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2981 — Snipe-IT: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2981</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Snipe-IT ausnutzen, um beliebigen Code auszuführen, erweiterte Berechtigungen zu erlangen, Sicherheitsmaßnahmen zu umgehen, Cross-Site-Scripting-Angriffe zu starten, sensible Informationen offenzulegen, Daten zu manipulieren, Konten zu übernehmen oder Denial-of-Service-Zustände herbeizuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Snipe-IT ausnutzen, um beliebigen Code auszuführen, erweiterte Berechtigungen zu erlangen, Sicherheitsmaßnahmen zu umgehen, Cross-Site-Scripting-Angriffe zu starten, sensible Informationen offenzulegen, Daten zu manipulieren, Konten zu übernehmen oder Denial-of-Service-Zustände herbeizuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2981</guid>
    </item>
  </channel>
</rss>
