HIGH🇵🇱 Wersja polska

CVE-2025-67493

CVSS 7.5v3.1pub. 2025-12-17upd. 2026-01-30

Homarr is an open-source dashboard. Prior to version 1.45.3, it was possible to craft an input which allowed privilege escalation and getting access to groups of other users due to missing sanitization of inputs in ldap search query. The vulnerability could impact all instances using ldap authentication where a malicious actor had access to a user account. Version 1.45.3 has a patch for the issue.

CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:L
  • Homarr

    APP
    Homarr
    < 1.45.3
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
LPE
CWE
References

Related vulnerabilities

CVE-2025-54313HIGH7.5⚠ KEVsame product

eslint-config-prettier 8.10.1, 9.1.1, 10.1.6, and 10.1.7 has embedded malicious code for a supply chain compro...

CVE-2026-33510HIGH8.8same product

Homarr is an open-source dashboard. Prior to 1.57.0, a DOM-based Cross-Site Scripting (XSS) vulnerability has ...

CVE-2025-64759HIGH8.1same product

Homarr is an open-source dashboard. Prior to version 1.43.3, stored XSS vulnerability exists, allowing the exe...

CVE-2026-32602MEDIUM4.2same product

Homarr to otwartoźródłowy dashboard. Przed wersją 1.57.0 endpoint rejestracji użytkownika (/api/trpc/user.regi...

CVE-2026-27796MEDIUM5.3same product

Homarr jest otwartym pulpitem nawigacyjnym. Przed wersją 1.54.0 endpoint integration.all tRPC w Homarr był nar...