CVE-2026-33510Patch(homarr / homarr)

LOWCVSS 8.8 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch homarr homarr systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Homarr is an open-source dashboard. Prior to 1.57.0, a DOM-based Cross-Site Scripting (XSS) vulnerability has been discovered in Homarr's /auth/login page. The application improperly trusts a URL parameter (callbackUrl), which is passed to redirect and router.push. An attacker can craft a malicious link that, when opened by an authenticated user, performs a client-side redirect and executes arbitrary JavaScript in the context of their browser. This could lead to credential theft, internal network pivoting, and unauthorized actions performed on behalf of the victim. This vulnerability is fixed in 1.57.0.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-87CWE-601

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • homarr

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 3 signals
  • Peaked at 2 mentions on most recent observed day (2026-04-07)
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
homarr

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-06: 1Mentions · 2026-04-07: 2Patch / Workaround · 2026-04-06: 1Patch / Workaround · 2026-04-07: 2Technical Details · 2026-04-06: 1Technical Details · 2026-04-07: 204-0604-07
Signal classification1 categories
Patch
3100.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-04-061
Patch1
2026-04-072
Patch2
Full discourse3 posts
  • Firmis Labs@FirmisLabs
    Patch

    CVE-2026-33510 · NIST 8.8/10 https://nvd.nist.gov/vuln/detail/CVE-2026-33510 ask your AI: "check if my project uses Homarr and if it's below version 1.57.0" then: "update Homarr to version 1.57.0 or later and make sure the dashboard and login flow still work"

    Post summary

    The message highlights CVE-2026-33510 with a CVSS score of 8.8/10 and recommends updating the Homarr application to version 1.57.0 or newer to address the vulnerability.

    1000028
    1 followersView on X
  • Firmis Labs@FirmisLabs
    Patch

    CVE-2026-33510 · NIST 8.8/10 https://nvd.nist.gov/vuln/detail/CVE-2026-33510 ask your AI: "check if my project uses Homarr and if it's below version 1.57.0" then: "update Homarr to version 1.57.0 or later and make sure the dashboard and login flow still work"

    Post summary

    The text references CVE-2026-33510 and urges users to update Homarr to version 1.57.0 or later, citing an NVD link and a high CVSS score of 8.8/10. No exploit or active usage is mentioned.

    1000029
    1 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-33510: HIGH] Beware of Homarr dashboard vulnerabilities - an XSS flaw in /auth/login page allowed for malicious link hijacking. Update to version 1.57.0 for secure browsing.#cve,CVE-2026-33510,#cybersecurity https://cvefind.com/CVE-2026-33510

    Post summary

    An advisory warns of an XSS vulnerability in Homarr dashboard and recommends updating to version 1.57.0 to mitigate the issue.

    0000035
    619 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apphomarrhomarr---

Explore more