PT-2026-30629 · Homarr · Homarr

Trebledj

·

Published

2026-04-06

·

Updated

2026-04-07

·

CVE-2026-33510

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:L
Name of the Vulnerable Software and Affected Versions Homarr versions prior to 1.57.0
Description Homarr is an open-source dashboard. A DOM-based Cross-Site Scripting (XSS) issue exists in the /auth/login page. The application improperly trusts the callbackUrl URL parameter, which is used in redirect and router.push. An attacker can create a malicious link that, when opened by an authenticated user, redirects the user and executes arbitrary JavaScript code within their browser. This could lead to credential theft, internal network pivoting, and unauthorized actions performed on behalf of the victim.
Recommendations Update to version 1.57.0 or later.

Exploit

Fix

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-33510

Affected Products

Homarr