Home
Description
Snipe-IT before version 8.3.3 contains a remote code execution vulnerability that allows an authenticated attacker to upload a malicious backup file containing arbitrary files and execute system commands.
References
github.com/grokability/snipe-it/pull/17966
github.com/grokability/snipe-it/releases/tag/v8.3.3
dappsec.substack.com/p/snipe-it-post-authenticated-remote
fptcloud.com/en/cve-2025-63601-proof-of-concept/
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.