SSRF Vulnerability in Homarr Dashboard by Homarr Labs
CVE-2026-27797
5.3MEDIUM
What is CVE-2026-27797?
The Homarr Dashboard, an open-source solution, contains a Server-Side Request Forgery (SSRF) vulnerability in versions prior to 1.54.0. This issue allows an unauthenticated remote attacker to manipulate the Homarr server into making arbitrary outbound HTTP requests. Such exploitation could lead to unauthorized access to internal network resources, potentially exposing sensitive data or services. The vulnerability has been addressed and patched in version 1.54.0. Users are encouraged to upgrade promptly to mitigate any risk posed by this security flaw.
Affected Version(s)
homarr < 1.54.0
