MEDIUM🇵🇱 Wersja polska

CVE-2026-27796

CVSS 5.3v3.1pub. 2026-03-07upd. 2026-03-10

Homarr is an open-source dashboard. Prior to version 1.54.0, the integration.all tRPC endpoint in Homarr is exposed as a publicProcedure, allowing unauthenticated users to retrieve a complete list of configured integrations. This metadata includes sensitive information such as internal service URLs, integration names, and service types. This issue has been patched in version 1.54.0.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
  • Homarr

    APP
    Homarr
    < 1.54.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2025-54313HIGH7.5⚠ KEVsame product

eslint-config-prettier 8.10.1, 9.1.1, 10.1.6, and 10.1.7 has embedded malicious code for a supply chain compro...

CVE-2026-33510HIGH8.8same product

Homarr is an open-source dashboard. Prior to 1.57.0, a DOM-based Cross-Site Scripting (XSS) vulnerability has ...

CVE-2025-67493HIGH7.5same product

Homarr is an open-source dashboard. Prior to version 1.45.3, it was possible to craft an input which allowed p...

CVE-2025-64759HIGH8.1same product

Homarr is an open-source dashboard. Prior to version 1.43.3, stored XSS vulnerability exists, allowing the exe...

CVE-2026-32602MEDIUM4.2same product

Homarr to otwartoźródłowy dashboard. Przed wersją 1.57.0 endpoint rejestracji użytkownika (/api/trpc/user.regi...