CVE 7.5 HIGH

Homarr issing input sanitization and possible privilege escalation through ldap search query injection_CVE-2025-67493

7.5 / 10
HIGH
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:L

Description

Homarr is an open-source dashboard. Prior to version 1.45.3, it was possible to craft an input which allowed privilege escalation and getting access to groups of other users due to missing sanitization of inputs in ldap search query. The vulnerability could impact all instances using ldap authentication where a malicious actor had access to a user account. Version 1.45.3 has a patch for the issue.

Basic Information

ID CVE-2025-67493
Source GitHub_M
Published Dec 17, 2025 at 21:09

Affected Product

Vendor homarr-labs
Product homarr
Version < 1.45.3
Affected Versions homarr-labs homarr < 1.45.3

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.