Detects Snipe-IT installations at 8.6.3 or earlier, where any authenticated user holding a pending checkout acceptance can read arbitrary server-readable files and drive arbitrary server-side HTTP requests. The acceptance note is rendered through Blade's {{ $note }}, which escapes HTML metacharacters but not markdown ones, so image syntax such as  survives into Laravel's mail::table component, is expanded by CommonMark into a real <img src> tag, and is then resolved by eduardokum/laravel-mail-auto-embed via file_get_contents() for local paths or curl for URLs. The fetched bytes are attached to the outbound notification, which the attacker receives by ticking 'send me a copy'. A default install leaks APP_KEY, the key behind Laravel's signed URLs and encrypted session cookies, so the impact is identity forgery rather than disclosure alone. Auto-embed needs no operator opt-in: no shipped .env sets the enable flag. Exploitation is blind, so proof comes from an out-of-band canary callback. Upgrade to Snipe-IT 8.7.0 or later.
Is your app exploitable through CVE-2026-86751?
Scan your domain free