Snipe-IT before version 8.3.3 contains a remote code execution vulnerability that allows an authenticated attacker to upload a malicious backup file containing arbitrary files and execute system commands.
References
Configurations
History
01 Dec 2025, 16:15
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
10 Nov 2025, 17:15
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
07 Nov 2025, 19:52
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Snipeitapp snipe-it
Snipeitapp |
|
| CPE | cpe:2.3:a:snipeitapp:snipe-it:*:*:*:*:*:*:*:* | |
| References | () https://github.com/grokability/snipe-it/pull/17966 - Issue Tracking, Patch | |
| References | () https://github.com/grokability/snipe-it/releases/tag/v8.3.3 - Release Notes |
06 Nov 2025, 19:45
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-11-05 16:15
Updated : 2025-12-01 16:15
NVD link : CVE-2025-63601
Mitre link : CVE-2025-63601
CVE.ORG link : CVE-2025-63601
JSON object : View
Products Affected
snipeitapp
- snipe-it
CWE
CWE-434
Unrestricted Upload of File with Dangerous Type
