Snipe-IT's import created_by can be overwritten
Moderate severity
GitHub Reviewed
Published
Jun 24, 2026
in
grokability/snipe-it
•
Updated Aug 28, 2026
Description
Published by the National Vulnerability Database
Jul 10, 2026
Published to the GitHub Advisory Database
Aug 28, 2026
Reviewed
Aug 28, 2026
Last updated
Aug 28, 2026
Impact
The
created_byof an import file can be arbitrarily overwritten via the Importer API endpoint by a user with CSV import capabilities who also has a valid API key.References