CVE-2026-86745 | Grokability Snipe-IT up to 8.6.3 CSV Export location-scoping-report.csv downloadLocationScopingReport csv injection
A vulnerability categorized as problematic has been discovered in Grokability Snipe-IT up to 8.6.3. This issue affects the function SettingsController::downloadLocationScopingReport of the file /admin/settings/location-scoping-report.csv of the component CSV Export. The manipulation of the argument item name/asset tag/serial/item/location company name/location name results in csv injection.
This vulnerability is cataloged as CVE-2026-86745. The attack may be launched remotely. There is no exploit available.
It is advisable to upgrade the affected component.VulDB Recent EntriesRead More