CVE-2026-26272Disclosure(sysadminsmedia / homebox)

LOWCVSS 5.4 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

HomeBox is a home inventory and organization system. Prior to 0.24.0-rc.1, a stored cross-site scripting (XSS) vulnerability exists in the item attachment upload functionality. The application does not properly validate or restrict uploaded file types, allowing an authenticated user to upload malicious HTML or SVG files containing executable JavaScript (also, potentially other formats that render scripts). Uploaded attachments are accessible via direct links. When a user accesses such a file in their browser, the embedded JavaScript executes in the context of the application's origin. This vulnerability is fixed in 0.24.0-rc.1.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • homebox

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-03-03); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Products
homebox

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-03: 2Mentions · 2026-03-04: 1Technical Details · 2026-03-03: 2Technical Details · 2026-03-04: 103-0303-04
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-032
Disclosure2
2026-03-041
General1
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-26272 Stored XSS Vulnerability in HomeBox Item Attachment Upload Functionality https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-26272

    Post summary

    The text announces a stored XSS vulnerability in HomeBox’s item attachment upload functionality, but provides no further details on exploitation, mitigation, or proof of concept.

    0001060
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-26272 HomeBox is a home inventory and organization system. Prior to 0.24.0-rc.1, a stored cross-site scripting (XSS) vulnerability exists in the item attachment upload func… https://www.cve.org/CVERecord?id=CVE-2026-26272

    Post summary

    The text announces a stored XSS vulnerability in HomeBox before version 0.24.0‑rc.1, providing technical details but no PoC, exploit, or patch information.

    00010393
    56.6K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-26272 HomeBox is a home inventory and organization system. Prior to 0.24.0-rc.1, a stored cross-site scripting (XSS) vulnerability exists in the item attachment upload func… https://www.cve.org/CVERecord?id=CVE-2026-26272 ----- Traducción: CVE-2026-26272 Hom… http://infoflow.cloud`

    Post summary

    The post announces CVE‑2026‑26272, a stored XSS flaw in HomeBox before version 0.24.0‑rc.1, and links to the CVE record but provides no exploitation or mitigation details.

    0000043
    55 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appsysadminsmediahomebox---

Explore more