Snipe-IT has a path traversal vulnerability via CSV import `image` field
Description
Published by the National Vulnerability Database
Jul 10, 2026
Published to the GitHub Advisory Database
Aug 28, 2026
Reviewed
Aug 28, 2026
Last updated
Aug 28, 2026
Impact
An authenticated user holding the
importandassets.updatepermissions can delete arbitrary files on the server filesystem by injecting a path traversal string into an asset'simagefield via CSV import, then triggering the image deletion feature.References