Server-Side Request Forgery in Homarr Dashboard by Homarr Labs
CVE-2026-25123
5.3MEDIUM
What is CVE-2026-25123?
The Homarr dashboard prior to version 1.52.0 contains a vulnerability where a public, unauthenticated tRPC endpoint, named widget.app.ping, accepts arbitrary URLs, resulting in server-side requests to those URLs. This flaw permits unauthenticated attackers to execute outbound HTTP requests from the Homarr server, which may expose the server to SSRF attacks and could enable attackers to determine the state of internal ports through response codes. The vulnerability has been addressed in version 1.52.0.
Affected Version(s)
homarr < 1.52.0
