Open source asset management system built on Laravel.
84%
Total Score
healthy
Healthy, backed by active maintenance and broad project activity; workflow supply-chain pinning is the main caveat.
The package runs post-autoload-dump and post-create-project-cmd scripts during Composer operations. These are relevant install-time behavior for a Laravel application and warrant awareness, but the signal alone does not show unsafe behavior.
Although 21 contributors were active, one contributor made about 90% of the recent commits. The organization-owned project provides some handoff capacity, but this concentration remains a maintenance resilience concern.
All 11 workflows were analyzed successfully, with no untrusted checkout or script-injection findings. However, one high-confidence finding identifies an unpinned container image, and 30 of 36 action references are unpinned, leaving avoidable build-integrity risk.
| Title | Versions | Severity |
|---|---|---|
CVE-2026-63498 snipe/snipe-it is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 8.7.0. | 0.0.0 - 8.7.0 | High |
CVE-2026-62368 snipe/snipe-it is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 8.7.0. | 0.0.0 - 8.7.0 | High |
CVE-2026-63493 snipe/snipe-it is vulnerable to Authentication Bypass Using an Alternate Path or Channel in versions 0.0.0 - 8.7.0. | 0.0.0 - 8.7.0 | High |
CVE-2026-55843 snipe/snipe-it is vulnerable to Improper Privilege Management in versions 0.0.0 - 8.6.0. | 0.0.0 - 8.6.0 | Medium |
CVE-2026-55516 snipe/snipe-it is vulnerable to Authorization Bypass Through User-Controlled Key in versions 0.0.0 - 8.6.1. | 0.0.0 - 8.6.1 | High |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
league/csv Version ^9.5 | — | — |
maknz/slack Version ^1.7 | — | — |
doctrine/dbal Version ^2.10 | — | — |
nesbot/carbon Version ^2.32 | — | — |
doctrine/cache Version ^1.10 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.