CVE-2022-23064High· 8.8▾ Twilightsnipe-IT vulnerable to host header injection
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 48.4 · likelihood 0.3 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 24.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
Last analysed / modified upstream
1.3%
Snipe-IT is a free, open-source IT asset/license management systemIn Snipe-IT, versions v3.0-alpha to v5.3.7 are vulnerable to Host Header Injection. By sending a specially crafted host header in the reset password request, it is possible to send password reset links to users which once clicked lead to an attacker controlled server and thus leading to password reset token leak. This can lead to account take over.
snipe/snipe-it >= 3.0-alpha, <= 5.3.7Upgrade to a patched release:
snipe/snipe-it 5.3.8Connected by shared product, vendor, weakness, or advisory.
CVE-2026-54329High· 8.5Snipe-IT API Vulnerable to Cross-Tenant Accessory Injection
CVE-2026-62368High· 8.1Snipe-IT is an IT asset/license management system
CVE-2026-63493High· 8.6Snipe-IT is an IT asset/license management system
CVE-2026-55843High· 6.5Snipe-IT has an Improper Privilege Management issue
CVE-2026-55460High· 7.1Snipe-IT has an authorization bypass on bulk editing users
CVE-2026-55464Medium· 5.4Snipe-IT vulnerable to stored XSS via Markdown custom field