CVE-2026-55469: Snipe-IT has a path traversal vulnerability via CSV import `image` field
An authenticated user holding the import and assets.update permissions can delete arbitrary files on the server filesystem by injecting a path traversal string into an asset’s image field via CSV import, then triggering the image deletion feature.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-55469 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →