CVE-2025-64759
Last modified
CVE-2025-64759 is a medium-severity vulnerability rated 6.1/10 on the CVSS scale. Homarr is an open-source dashboard. Prior to version 1.43.3, stored XSS vulnerability exists, allowing the execution of arbitrary JavaScript in a user's browser, with minimal or no user interaction required, due to the rendering of a malicious uploaded SVG file. EPSS estimates a 0.27% chance of exploitation in the next 30 days.
Description
Homarr is an open-source dashboard. Prior to version 1.43.3, stored XSS vulnerability exists, allowing the execution of arbitrary JavaScript in a user's browser, with minimal or no user interaction required, due to the rendering of a malicious uploaded SVG file. This could be abused to add an attacker's account to the "credentials-admin" group, giving them full administrative access, if a user logged in as an administrator was to view the page which renders or redirects to the SVG. This issue has been patched in version 1.43.3.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Homarr | Homarr | < 1.43.3 |
References
- https://github.com/homarr-labs/homarr/commit/aaa23f37321be1e110f722b36889b2fd3bea2059Patch, Permissions Required
- https://github.com/homarr-labs/homarr/security/advisories/GHSA-wj62-c5gr-2x53Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-64759?
How severe is CVE-2025-64759?
How do I fix CVE-2025-64759?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-64753grist-core is a spreadsheet hosting server. Prior to version…6.5
- CVE-2025-64754Jitsi Meet is an open source video conferencing application.…2.7
- CVE-2025-64755Claude Code is an agentic coding tool. Prior to version 2.0.…9.8
- CVE-2025-64756Glob matches files using patterns the shell uses. Starting i…7.5
- CVE-2025-64757Astro is a web framework. Prior to version 5.14.3, a vulnera…3.5
- CVE-2025-64758@dependencytrack/frontend is a Single Page Application (SPA)…4.8
- CVE-2025-6476A vulnerability was found in SourceCodester Gym Management S…4.3
- CVE-2025-64760Tuleap is a free and open source suite for management of sof…4.3
- CVE-2025-64761OpenBao is an open source identity-based secrets management …7.2
- CVE-2025-64762The AuthKit library for Next.js provides convenient helpers …9.1
- CVE-2025-64763Envoy is a high-performance edge/middle/service proxy. In 1.…5.3
- CVE-2025-64764Astro is a web framework. Prior to version 5.15.8, a reflect…5.4
Are you affected by CVE-2025-64759?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
