Snipe-IT Unsafe Deserialization Vulnerability

Vulnerability

A vulnerability allowing unsafe deserialization has been identified in Snipe-IT versions prior to 8.1.18. This issue could potentially be exploited to manipulate the application's behavior or data processing.

Impact

Exploitation of this vulnerability could lead to arbitrary code execution or other unintended consequences, such as data manipulation, depending on the context in which the deserialization occurs.

Remediation

Users can upgrade to Snipe-IT version 8.1.18 or later, which includes a fix for the unsafe deserialization vulnerability.

Added: Sep 19, 2025, 3:19 AM
Updated: Sep 19, 2025, 3:19 AM

Vulnerability Rating

Custom Algorithm
spread
3.1
impact
10.0
exploitability
5.2
remediation
7.7
relevance
0.6
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.