
CVE-2026-25123 Homarr is an open-source dashboard. Prior to 1.52.0, a public (unauthenticated) tRPC endpoint http://widget.app.ping accepts an arbitrary url and performs a server-side requ… https://www.cve.org/CVERecord?id=CVE-2026-25123
Post summary
The CVE reveals a server‑side request forgery in Homarr's tRPC endpoint prior to version 1.52.0, enabling unauthenticated arbitrary URL requests.
