MEDIUM🇬🇧 English

CVE-2026-32602

CVSS 4.2v3.1pub. 2026-04-06upd. 2026-04-10

Homarr to otwartoźródłowy dashboard. Przed wersją 1.57.0 endpoint rejestracji użytkownika (/api/trpc/user.register) był podatny na race condition umożliwiającą atakującemu utworzenie wielu kont użytkownika z wykorzystaniem jednokrotnego tokenu zaproszenia. Przepływ rejestracji wykonywał trzy sekwencyjne operacje bazodanowe bez transakcji: CHECK, CREATE i DELETE. Ponieważ operacje nie były atomowe, współbieżne żądania mogły przejść etap walidacji (1) zanim którekolwiek z nich dotarło do etapu usunięcia (3). Pozwalało to zarejestrować wiele kont przy użyciu tokenu zaproszenia przeznaczonego do jednokrotnego użytku. Podatność została usunięta w wersji 1.57.0.

Pokaż oryginał (EN)

Homarr is an open-source dashboard. Prior to 1.57.0, the user registration endpoint (/api/trpc/user.register) is vulnerable to a race condition that allows an attacker to create multiple user accounts from a single-use invite token. The registration flow performs three sequential database operations without a transaction: CHECK, CREATE, and DELETE. Because these operations are not atomic, concurrent requests can all pass the validation step (1) before any of them reaches the deletion step (3). This allows multiple accounts to be registered using a single invite token that was intended to be single-use. This vulnerability is fixed in 1.57.0.

CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
  • Homarr

    APP
    Homarr
    < 1.57.0
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Tagi
Race Condition
CWE
Referencje

Powiązane podatności

CVE-2025-54313HIGH7.5⚠ KEVten sam produkt

eslint-config-prettier 8.10.1, 9.1.1, 10.1.6, and 10.1.7 has embedded malicious code for a supply chain compro...

CVE-2026-33510HIGH8.8ten sam produkt

Homarr is an open-source dashboard. Prior to 1.57.0, a DOM-based Cross-Site Scripting (XSS) vulnerability has ...

CVE-2025-67493HIGH7.5ten sam produkt

Homarr is an open-source dashboard. Prior to version 1.45.3, it was possible to craft an input which allowed p...

CVE-2025-64759HIGH8.1ten sam produkt

Homarr is an open-source dashboard. Prior to version 1.43.3, stored XSS vulnerability exists, allowing the exe...

CVE-2026-27796MEDIUM5.3ten sam produkt

Homarr jest otwartym pulpitem nawigacyjnym. Przed wersją 1.54.0 endpoint integration.all tRPC w Homarr był nar...