Mend.io Vulnerability Database
The largest open source vulnerability database
What is a Vulnerability ID?
New vulnerability? Tell us about it!
WS-2022-0345
Published:May 15, 2026
Updated:May 15, 2026
CSV Injection in CSV files generated by the backend in snipe/snipe-it. Formula Elements are not sanitized before adding to CSV reports. This leads to CSV formula injection.
Affected Packages
snipe/snipe-it (PHP):
Affected version(s) =dev-fixes/nested_location_selectlist <dev-fixes/no-NO-language
Fix Suggestion:
Update to version dev-fixes/no-NO-language
snipe/snipe-it (PHP):
Affected version(s) =dev-features/better_depreciation_displays_and_api <dev-features/blade_component_for_submit
Fix Suggestion:
Update to version dev-features/blade_component_for_submit
snipe/snipe-it (PHP):
Affected version(s) >=dev-snyk-upgrade-226c28b0a47b6b2249169e44ad3f5ccc <v5.4.0
Fix Suggestion:
Update to version v5.4.0
snipe/snipe-it (PHP):
Affected version(s) =dev-features/bulk_asset_checkin_from_list_view <dev-features/bulk_update_asset_name
Fix Suggestion:
Update to version dev-features/bulk_update_asset_name
snipe/snipe-it (PHP):
Affected version(s) =dev-snyk-upgrade-d9b3d5060f9cd6bdfb081bded58ce6a6 <dev-snyk-upgrade-919d35b4cfc5d350dfdf05ea3ddd6dc5
Fix Suggestion:
Update to version dev-snyk-upgrade-919d35b4cfc5d350dfdf05ea3ddd6dc5
snipe/snipe-it (PHP):
Affected version(s) =dev-possible_fix_for_logout <dev-print_view_improvements
Fix Suggestion:
Update to version dev-print_view_improvements
snipe/snipe-it (PHP):
Affected version(s) =dev-snyk-fix-4fe443a92c8dea8fb137fbe1be558300 <dev-snyk-fix-3c0a826cc3528a757a82b73bdac60569
Fix Suggestion:
Update to version dev-snyk-fix-3c0a826cc3528a757a82b73bdac60569
snipe/snipe-it (PHP):
Affected version(s) =dev-snyk-fix-76e90d2881929f98caa2a384c451971b <dev-snyk-fix-432e0a4538aab56f58cbaf50561d2000
Fix Suggestion:
Update to version dev-snyk-fix-432e0a4538aab56f58cbaf50561d2000
snipe/snipe-it (PHP):
Affected version(s) =dev-integration <dev-jerk_prevention
Fix Suggestion:
Update to version dev-jerk_prevention
snipe/snipe-it (PHP):
Affected version(s) =dev-snyk-fix-d1c9fd7a6f3b8db3155938935de36b39 <dev-snyk-upgrade-1377cc2d38a76585c814757398543f5f
Fix Suggestion:
Update to version dev-snyk-upgrade-1377cc2d38a76585c814757398543f5f
snipe/snipe-it (PHP):
Affected version(s) =dev-snyk-upgrade-0f46dbb6c110d0a1cbc822b2daa65af1 <dev-snyk-upgrade-9e05d779a6887be31bf62c8514869d05
Fix Suggestion:
Update to version dev-snyk-upgrade-9e05d779a6887be31bf62c8514869d05
snipe/snipe-it (PHP):
Affected version(s) >=dev-improve_ldap_search_error_reporting <dev-improve_safety_csv_charset_detection
Fix Suggestion:
Update to version dev-improve_safety_csv_charset_detection
snipe/snipe-it (PHP):
Affected version(s) >=dev-features/sticky_column <dev-features/switch_dash_pie_to_status_type
Fix Suggestion:
Update to version dev-features/switch_dash_pie_to_status_type
snipe/snipe-it (PHP):
Affected version(s) =dev-fixes/added_gitkeep_to_eula_pdfs <dev-fixes/added_help_text_to_support_url
Fix Suggestion:
Update to version dev-fixes/added_help_text_to_support_url
snipe/snipe-it (PHP):
Affected version(s) =dev-fixes/fa_map_icon_in_chrome <dev-fixes/fail_with_error_when_uploaded_file_does_not_exist
Fix Suggestion:
Update to version dev-fixes/fail_with_error_when_uploaded_file_does_not_exist
snipe/snipe-it (PHP):
Affected version(s) =dev-bug/ch15774/black-mode-is-unreadable-in-list-views <dev-bug/check_for_valid_category_on_print
Fix Suggestion:
Update to version dev-bug/check_for_valid_category_on_print
snipe/snipe-it (PHP):
Affected version(s) =dev-snyk-fix-85f5adade942b5157bf57dab1c12889c <dev-snyk-upgrade-291b556667d6ffe966495405775b3255
Fix Suggestion:
Update to version dev-snyk-upgrade-291b556667d6ffe966495405775b3255
snipe/snipe-it (PHP):
Affected version(s) =dev-fixes/fix-for-css-on-column-selector <dev-fixes/fix_crash_on_purged_models_in_activity_report
Fix Suggestion:
Update to version dev-fixes/fix_crash_on_purged_models_in_activity_report
snipe/snipe-it (PHP):
Affected version(s) =dev-dependabot/github_actions/docker/build-push-action-3 <dev-dependabot/github_actions/docker/login-action-3
Fix Suggestion:
Update to version dev-dependabot/github_actions/docker/login-action-3
snipe/snipe-it (PHP):
Affected version(s) =dev-snyk-upgrade-606115776482fcac3576ea931ec2f582 <dev-uberbrady-patch-2
Fix Suggestion:
Update to version dev-uberbrady-patch-2
snipe/snipe-it (PHP):
Affected version(s) =dev-features/more_normal_consumables_api <dev-features/more_strictly_disallow_non_slack_checkout_hooks
Fix Suggestion:
Update to version dev-features/more_strictly_disallow_non_slack_checkout_hooks
snipe/snipe-it (PHP):
Affected version(s) =v4.4.0 <dev-dependabot/github_actions/develop/codacy/codacy-analysis-cli-action-4.4.1
Fix Suggestion:
Update to version dev-dependabot/github_actions/develop/codacy/codacy-analysis-cli-action-4.4.1
snipe/snipe-it (PHP):
Affected version(s) =dev-snyk-fix-25f738095fc3f4dea25af61f5af7df99 <dev-snyk-upgrade-9e465161f7c9fd096a214ca3ad2fae7b
Fix Suggestion:
Update to version dev-snyk-upgrade-9e465161f7c9fd096a214ca3ad2fae7b
snipe/snipe-it (PHP):
Affected version(s) >=v4.4.1 <v4.7.5
Fix Suggestion:
Update to version v4.7.5
snipe/snipe-it (PHP):
Affected version(s) =dev-snyk-upgrade-a38b61e5dc82c98d52041a0c1b5b2da0 <dev-snyk-upgrade-f710172d80462b13e2afd012e062cd5d
Fix Suggestion:
Update to version dev-snyk-upgrade-f710172d80462b13e2afd012e062cd5d
snipe/snipe-it (PHP):
Affected version(s) =dev-snyk-upgrade-19a3757d542372e092f6a139638d9e21 <dev-snyk-upgrade-680ee784d792d1583ed7eaf1f139f2ce
Fix Suggestion:
Update to version dev-snyk-upgrade-680ee784d792d1583ed7eaf1f139f2ce
snipe/snipe-it (PHP):
Affected version(s) =dev-features/experimental_labels <dev-features/google_socialite
Fix Suggestion:
Update to version dev-features/google_socialite
snipe/snipe-it (PHP):
Affected version(s) >=dev-l10n_develop <dev-snyk-upgrade-1297c81120d7d845e0fabbe492211d66
Fix Suggestion:
Update to version dev-snyk-upgrade-1297c81120d7d845e0fabbe492211d66
snipe/snipe-it (PHP):
Affected version(s) =dev-revert-11663-fixes/user_cant_be_deleted_if_has_consumables <dev-revert-12165-fixes/custom_fields_values
Fix Suggestion:
Update to version dev-revert-12165-fixes/custom_fields_values
snipe/snipe-it (PHP):
Affected version(s) =dev-fix_depreciation_report_v5 <dev-snyk-fix-109de929f33df8035195d2e8d005af8b
Fix Suggestion:
Update to version dev-snyk-fix-109de929f33df8035195d2e8d005af8b
snipe/snipe-it (PHP):
Affected version(s) =dev-fixes/gate_for_kits_nonsuperadmin <dev-fixes/handle_arrays_on_validation_failure
Fix Suggestion:
Update to version dev-fixes/handle_arrays_on_validation_failure
snipe/snipe-it (PHP):
Affected version(s) =dev-fixes/set_default_ldap_version <dev-fixes/show_error_when_assigned_to_not_null_but_type_is_null
Fix Suggestion:
Update to version dev-fixes/show_error_when_assigned_to_not_null_but_type_is_null
snipe/snipe-it (PHP):
Affected version(s) =dev-backup_migrator <dev-better_handle_inline_files
Fix Suggestion:
Update to version dev-better_handle_inline_files
snipe/snipe-it (PHP):
Affected version(s) >=dev-dependabot/github_actions/docker/metadata-action-4 <v4.1.5
Fix Suggestion:
Update to version v4.1.5
snipe/snipe-it (PHP):
Affected version(s) >=v4.1.6 <dev-dependabot/github_actions/codacy/codacy-analysis-cli-action-4.2.0
Fix Suggestion:
Update to version dev-dependabot/github_actions/codacy/codacy-analysis-cli-action-4.2.0
snipe/snipe-it (PHP):
Affected version(s) =dev-features/added_number_format_to_tab_badges <dev-features/added_phone_fax_to_locations
Fix Suggestion:
Update to version dev-features/added_phone_fax_to_locations
snipe/snipe-it (PHP):
Affected version(s) =dev-fixes/use_db_column_instead_of_converted_value <dev-fixes/use_more_modern_request_syntax_in_blades
Fix Suggestion:
Update to version dev-fixes/use_more_modern_request_syntax_in_blades
snipe/snipe-it (PHP):
Affected version(s) =dev-fixes/api_throttling <dev-fixes/array_key_in_import
Fix Suggestion:
Update to version dev-fixes/array_key_in_import
snipe/snipe-it (PHP):
Affected version(s) =dev-fixes/update_routes <dev-fixes/updated_apple_url
Fix Suggestion:
Update to version dev-fixes/updated_apple_url
snipe/snipe-it (PHP):
Affected version(s) =dev-features/adds_unescaper_to_execute <dev-features/adds_users_consumables_endpoint
Fix Suggestion:
Update to version dev-features/adds_users_consumables_endpoint
snipe/snipe-it (PHP):
Affected version(s) =dev-fix_deprecation_report <dev-fix_for_qr_on_old_label_engine
Fix Suggestion:
Update to version dev-fix_for_qr_on_old_label_engine
snipe/snipe-it (PHP):
Affected version(s) =dev-snyk-upgrade-0005397ba83c98631126ff98d5471e6d <dev-snyk-upgrade-f577261903c8b2bcda8908451c578b66
Fix Suggestion:
Update to version dev-snyk-upgrade-f577261903c8b2bcda8908451c578b66
snipe/snipe-it (PHP):
Affected version(s) >=v4.0-alpha <dev-dependabot/github_actions/actions/checkout-4
Fix Suggestion:
Update to version dev-dependabot/github_actions/actions/checkout-4
snipe/snipe-it (PHP):
Affected version(s) =dev-upgrade_select2 <v2.0
Fix Suggestion:
Update to version v2.0
snipe/snipe-it (PHP):
Affected version(s) =v3.0 <dev-dependabot/github_actions/actions/checkout-3.1.0
Fix Suggestion:
Update to version dev-dependabot/github_actions/actions/checkout-3.1.0
snipe/snipe-it (PHP):
Affected version(s) =dev-fixes/better_handle_bad_date_values <dev-fixes/better_handle_data_file_mismatch_in_user_files
Fix Suggestion:
Update to version dev-fixes/better_handle_data_file_mismatch_in_user_files
snipe/snipe-it (PHP):
Affected version(s) =dev-features/added_capture_tag_to_file_upload <dev-features/added_created_by_to_groups
Fix Suggestion:
Update to version dev-features/added_created_by_to_groups
snipe/snipe-it (PHP):
Affected version(s) =dev-develop-v6 <dev-develop-v6-integration
Fix Suggestion:
Update to version dev-develop-v6-integration
snipe/snipe-it (PHP):
Affected version(s) =dev-snyk-upgrade-354d4d4729c22cbbe5d63561e02e8cf9 <dev-v8_final_merge
Fix Suggestion:
Update to version dev-v8_final_merge
snipe/snipe-it (PHP):
Affected version(s) =dev-snyk-upgrade-880f0b8d533071d29c74b717094ac6ff <dev-snyk-upgrade-bd5b0beff2ee8fcecb36dce1879c6aa2
Fix Suggestion:
Update to version dev-snyk-upgrade-bd5b0beff2ee8fcecb36dce1879c6aa2
snipe/snipe-it (PHP):
Affected version(s) =dev-snyk-upgrade-024e246b67a996f99471215eb826285e <dev-snyk-upgrade-a83a4a1aa505b3530304a69dc8db7157
Fix Suggestion:
Update to version dev-snyk-upgrade-a83a4a1aa505b3530304a69dc8db7157
snipe/snipe-it (PHP):
Affected version(s) =dev-snyk-fix-a992b5202c0c6f1bc0166bb6963a1648 <dev-snyk-upgrade-0c59f405145c50aecd391737f21e1695
Fix Suggestion:
Update to version dev-snyk-upgrade-0c59f405145c50aecd391737f21e1695
snipe/snipe-it (PHP):
Affected version(s) =dev-feature/ch15660/nicer-formatting-of-the-page-if-custom-logout <dev-feature/google_login_more_prominent
Fix Suggestion:
Update to version dev-feature/google_login_more_prominent
snipe/snipe-it (PHP):
Affected version(s) =dev-snyk-fix-77c6e105b65be90c7f4726af85cc337f <dev-snyk-upgrade-9826430530842ed3fefb3dd1972343cc
Fix Suggestion:
Update to version dev-snyk-upgrade-9826430530842ed3fefb3dd1972343cc
snipe/snipe-it (PHP):
Affected version(s) >=v4.2.0 <dev-dependabot/github_actions/develop/codacy/codacy-analysis-cli-action-4.4.0
Fix Suggestion:
Update to version dev-dependabot/github_actions/develop/codacy/codacy-analysis-cli-action-4.4.0
snipe/snipe-it (PHP):
Affected version(s) >=v3.1.0 <dev-security/snyk_Upgrade-jspdf-autotable-from-3.8.1-to-3.8.2-14365
Fix Suggestion:
Update to version dev-security/snyk_Upgrade-jspdf-autotable-from-3.8.1-to-3.8.2-14365
snipe/snipe-it (PHP):
Affected version(s) =dev-fixes/smaller_padlock_on_table_header <dev-fixes/smarter_decryption_in_activity
Fix Suggestion:
Update to version dev-fixes/smarter_decryption_in_activity
snipe/snipe-it (PHP):
Affected version(s) =dev-feature/add_base_templates <dev-feature/ch15358/feature-request-allow-configurable-depreciation
Fix Suggestion:
Update to version dev-feature/ch15358/feature-request-allow-configurable-depreciation
snipe/snipe-it (PHP):
Affected version(s) >=v5.4.1 <dev-develop-v6-rc1
Fix Suggestion:
Update to version dev-develop-v6-rc1
snipe/snipe-it (PHP):
Affected version(s) =dev-features/accessories_users <dev-features/add_accept_pdf_to_asset_endpoint
Fix Suggestion:
Update to version dev-features/add_accept_pdf_to_asset_endpoint
snipe/snipe-it (PHP):
Affected version(s) =dev-rebased_added_gitkeep_to_to_eula_pdfs <dev-redirect-on-print-if-user-invalid
Fix Suggestion:
Update to version dev-redirect-on-print-if-user-invalid
snipe/snipe-it (PHP):
Affected version(s) =dev-revert-11016-patch-1 <dev-fixes/pr_12106_missing_slash_for_stdClass
Fix Suggestion:
Update to version dev-fixes/pr_12106_missing_slash_for_stdClass
snipe/snipe-it (PHP):
Affected version(s) =dev-snyk-upgrade-f4b6c42dd687561a48fbbd915415d6d1 <dev-snyk-upgrade-23af2ac368155dc386040447ab4dee5e
Fix Suggestion:
Update to version dev-snyk-upgrade-23af2ac368155dc386040447ab4dee5e
snipe/snipe-it (PHP):
Affected version(s) =dev-master <dev-more_print_fixes
Fix Suggestion:
Update to version dev-more_print_fixes
snipe/snipe-it (PHP):
Affected version(s) >=dev-dependabot/github_actions/docker/login-action-2 <dev-fixes/added_2fa_string
Fix Suggestion:
Update to version dev-fixes/added_2fa_string
snipe/snipe-it (PHP):
Affected version(s) =dev-features/nicer_ui_for_groups <dev-features/nicer_view_assets_ui_for_regular_users
Fix Suggestion:
Update to version dev-features/nicer_view_assets_ui_for_regular_users
snipe/snipe-it (PHP):
Affected version(s) >=v3.0-alpha <dev-dependabot/github_actions/actions/checkout-3
Fix Suggestion:
Update to version dev-dependabot/github_actions/actions/checkout-3
snipe/snipe-it (PHP):
Affected version(s) >=v4.7.6 <dev-dependabot/github_actions/docker/build-push-action-5
Fix Suggestion:
Update to version dev-dependabot/github_actions/docker/build-push-action-5
snipe/snipe-it (PHP):
Affected version(s) =dev-fixes/fix_ldap_js <dev-fixes/fixed_accessory_not_found_string
Fix Suggestion:
Update to version dev-fixes/fixed_accessory_not_found_string
snipe/snipe-it (PHP):
Affected version(s) =dev-develop <dev-disallow_bad_group_data
Fix Suggestion:
Update to version dev-disallow_bad_group_data
snipe/snipe-it (PHP):
Affected version(s) >=v6.0.0 <v6.0.11
Fix Suggestion:
Update to version v6.0.11
snipe/snipe-it (PHP):
Affected version(s) =dev-snyk-upgrade-335c0c078a71db28e3cbc7d151e19ab6 <dev-fixes/support_apache_24
Fix Suggestion:
Update to version dev-fixes/support_apache_24
snipe/snipe-it (PHP):
Affected version(s) =dev-features/add_url_in_export <dev-features/add_warranty_link_even_if_no_warranty_set
Fix Suggestion:
Update to version dev-features/add_warranty_link_even_if_no_warranty_set
snipe/snipe-it (PHP):
Affected version(s) =dev-snyk-fix-16fb0964121e9f33a31ba2a5db2ff491 <dev-fixes/500_error_when_cloning_invalid_accessory
Fix Suggestion:
Update to version dev-fixes/500_error_when_cloning_invalid_accessory
snipe/snipe-it (PHP):
Affected version(s) =dev-snyk-upgrade-b2b26cf8ec7a697fe0094f699652a345 <dev-snyk-upgrade-c984383061fd11ea3aa23a32407aa002
Fix Suggestion:
Update to version dev-snyk-upgrade-c984383061fd11ea3aa23a32407aa002
snipe/snipe-it (PHP):
Affected version(s) =dev-snyk-upgrade-e4f7076f1b4be8ac5cadcc7632c45a0e <dev-snyk-upgrade-48895ab5d277cdb4eb4964f8cdb50fa9
Fix Suggestion:
Update to version dev-snyk-upgrade-48895ab5d277cdb4eb4964f8cdb50fa9
snipe/snipe-it (PHP):
Affected version(s) =dev-fixes/add_additional_curreny_formats_and_split_api_results <dev-fixes/add_json_to_mimes
Fix Suggestion:
Update to version dev-fixes/add_json_to_mimes
snipe/snipe-it (PHP):
Affected version(s) =dev-features/adds_ldap_import_and_assets_count_to_user_api <dev-features/adds_license_checkin_checkout_to_all_in_gui
Fix Suggestion:
Update to version dev-features/adds_license_checkin_checkout_to_all_in_gui
Do you need more information?
Contact Us
CVSS v4
Base Score:
6.9
Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
NONE
Vulnerable System Confidentiality
LOW
Vulnerable System Integrity
NONE
Vulnerable System Availability
NONE
Subsequent System Confidentiality
NONE
Subsequent System Integrity
NONE
Subsequent System Availability
NONE
CVSS v3
Base Score:
5.3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
LOW
Integrity
NONE
Availability
NONE