Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-xg82-2hrv-hf64 | Snipe-IT has insecure permissions in file uploads |
Tue, 12 May 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Snipeitapp
Snipeitapp snipe-it |
|
| CPEs | cpe:2.3:a:snipeitapp:snipe-it:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Snipeitapp
Snipeitapp snipe-it |
Thu, 07 May 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Insecure Permissions in Snipe‑IT Allow Remote Code Execution |
Thu, 07 May 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Insecure Permissions Allowing Remote Arbitrary Code Execution in Snipe‑IT | |
| Weaknesses | CWE-732 |
Thu, 07 May 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Grokability
Grokability snipe-it |
|
| Vendors & Products |
Grokability
Grokability snipe-it |
Thu, 07 May 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Insecure Permissions Allowing Remote Arbitrary Code Execution in Snipe‑IT | |
| Weaknesses | CWE-732 |
Thu, 07 May 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-284 | |
| Metrics |
cvssV3_1
|
Thu, 07 May 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Insecure Permissions vulnerability in grokability snipe-it v.8.4.0 and before and fixed after 2026-03-10 commit 676a9958 allows a remote attacker to execute arbitrary code via the app/Http/Controllers/Api/UploadedFilesController.php component | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-05-07T17:39:49.914Z
Reserved: 2026-04-06T00:00:00.000Z
Link: CVE-2026-37709
Updated: 2026-05-07T17:37:31.203Z
Status : Analyzed
Published: 2026-05-07T18:16:19.013
Modified: 2026-05-12T20:29:20.630
Link: CVE-2026-37709
No data.
OpenCVE Enrichment
Updated: 2026-05-07T21:45:36Z
Github GHSA