Vulnerability Description
Snipe-IT before version 8.3.3 contains a remote code execution vulnerability that allows an authenticated attacker to upload a malicious backup file containing arbitrary files and execute system commands.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Snipeitapp | Snipe-It | < 8.3.3 |
Related Weaknesses (CWE)
References
- https://dappsec.substack.com/p/snipe-it-post-authenticated-remote
- https://fptcloud.com/en/cve-2025-63601-proof-of-concept/
- https://github.com/grokability/snipe-it/pull/17966Issue TrackingPatch
- https://github.com/grokability/snipe-it/releases/tag/v8.3.3Release Notes
FAQ
What is CVE-2025-63601?
CVE-2025-63601 is a vulnerability with a CVSS score of 9.9 (CRITICAL). Snipe-IT before version 8.3.3 contains a remote code execution vulnerability that allows an authenticated attacker to upload a malicious backup file containing arbitrary files and execute system comma...
How severe is CVE-2025-63601?
CVE-2025-63601 has been rated CRITICAL with a CVSS base score of 9.9/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2025-63601?
Check the references section above for vendor advisories and patch information. Affected products include: Snipeitapp Snipe-It.