High severity8.1NVD Advisory· Published Nov 19, 2025· Updated Apr 14, 2026
CVE-2025-64759
CVE-2025-64759
Description
Homarr is an open-source dashboard. Prior to version 1.43.3, stored XSS vulnerability exists, allowing the execution of arbitrary JavaScript in a user's browser, with minimal or no user interaction required, due to the rendering of a malicious uploaded SVG file. This could be abused to add an attacker's account to the "credentials-admin" group, giving them full administrative access, if a user logged in as an administrator was to view the page which renders or redirects to the SVG. This issue has been patched in version 1.43.3.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- github.com/homarr-labs/homarr/commit/aaa23f37321be1e110f722b36889b2fd3bea2059nvdPatchPermissions Required
- github.com/homarr-labs/homarr/security/advisories/GHSA-wj62-c5gr-2x53nvdPatchVendor Advisory
News mentions
0No linked articles in our index yet.