CVE-2024-48987: Snipeitapp Snipe-It

Medium severity, CVSS 6.6. EPSS: 1% chance of exploitation in the next 30 days.

Snipe-IT before 7.0.10 allows remote code execution (associated with cookie serialization) when an attacker knows the APP_KEY. This is exacerbated by .env files, available from the product's repository, that have default APP_KEY values.

Affected products

  • Snipeitapp Snipe-It: before 7.0.10 (fixed in 7.0.10)

Published 2024-10-11. Last modified 2026-06-17.