Users with component view access could be impacted by an unescaped notes column.
This was patched in https://github.com/grokability/snipe-it/commit/28f493d84d057895fbb93b6570e7393a2c2fa438, and is fixed in v8.4.1 or greater.
None.
{
"github_reviewed": true,
"github_reviewed_at": "2026-05-08T22:23:41Z",
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"nvd_published_at": null
}