CVE-2026-86751
Analyzed Analyzed - Analysis Complete

Snipe-IT Markdown Image Injection Leading to File Read

Vulnerability report for CVE-2026-86751, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-09

Last updated on: 2026-09-14

Assigner: VulnCheck

Description

Snipe-IT before 8.7.0 fails to properly sanitize markdown image syntax in note fields, allowing authenticated users to read arbitrary server files and issue server-side HTTP requests. Attackers can submit markdown image syntax in checkout acceptance notes that survive HTML escaping, are expanded by CommonMark parser, and resolved by laravel-mail-auto-embed via file_get_contents or curl, exfiltrating sensitive files like .env containing APP_KEY.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-09
Last Modified
2026-09-14
Generated
2026-09-29
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-27
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
snipeitapp snipe-it to 8.7.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-73 The product allows user input to control or influence paths or file names that are used in filesystem operations.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects Snipe-IT versions before 8.7.0. It allows authenticated users to exploit improperly sanitized markdown image syntax in note fields to read arbitrary server files and perform server-side HTTP requests. The markdown image tags bypass HTML escaping and are processed by the CommonMark parser, which laravel-mail-auto-embed resolves using functions like file_get_contents or curl.

Detection Guidance
  • Check Snipe-IT version with: grep -r "version" /path/to/snipe-it/config/app.php or check the admin panel version display.
  • Review note fields in checkout acceptance for markdown image syntax like ![alt](/etc/passwd) or ![alt](file:///etc/hostname).
  • Inspect outbound emails for embedded file contents or unexpected URLs from laravel-mail-auto-embed processing.
  • Monitor server logs for unusual file_get_contents or curl requests targeting sensitive files.
Impact Analysis

Attackers can read sensitive files such as .env containing the APP_KEY, exfiltrate data, and issue server-side requests. This could lead to unauthorized access, data breaches, or further compromise of the system if exploited by authenticated users with pending checkout acceptance.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating GDPR's data protection principles and HIPAA's security requirements for protected health information. Non-compliance may result in legal penalties, reputational damage, and loss of trust.

Mitigation Strategies
  • Upgrade Snipe-IT to version 8.7.0 or later immediately to patch the vulnerability.
  • Disable markdown image syntax in note fields by applying the CommonMark extension update.
  • Audit all note fields and emails for signs of exploitation, especially .env file exfiltration.
  • Restrict file access permissions and review APP_KEY exposure if .env files were accessed.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-86751. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart