All verified exploits

CVE-2026-86751 Arbitrary File Read and SSRF via Markdown Image in Acceptance Notes

Pentest critical Snipe-IT Added cve-pentest-cve-2026-86751

Detects Snipe-IT installations at 8.6.3 or earlier, where any authenticated user holding a pending checkout acceptance can read arbitrary server-readable files and drive arbitrary server-side HTTP requests. The acceptance note is rendered through Blade's {{ $note }}, which escapes HTML metacharacters but not markdown ones, so image syntax such as ![x](/var/www/html/.env) survives into Laravel's mail::table component, is expanded by CommonMark into a real <img src> tag, and is then resolved by eduardokum/laravel-mail-auto-embed via file_get_contents() for local paths or curl for URLs. The fetched bytes are attached to the outbound notification, which the attacker receives by ticking 'send me a copy'. A default install leaks APP_KEY, the key behind Laravel's signed URLs and encrypted session cookies, so the impact is identity forgery rather than disclosure alone. Auto-embed needs no operator opt-in: no shipped .env sets the enable flag. Exploitation is blind, so proof comes from an out-of-band canary callback. Upgrade to Snipe-IT 8.7.0 or later.

Is your app exploitable through CVE-2026-86751?

Scan your domain free