- EPSS 0.24%
- Veröffentlicht 21.09.2026 17:44:41
- Zuletzt bearbeitet 29.09.2026 15:17:26
HomeBox is a home inventory and organization system. Prior to 0.26.0, the default-on BlockBogonNets and BlockCloudMetadata notifier SSRF protections in backend/internal/sys/validate/notifier_url.go do not inspect IPv4 destinations embedded in the NAT...
CVE-2026-48826
- EPSS -
- Veröffentlicht 21.09.2026 17:43:43
- Zuletzt bearbeitet 23.09.2026 18:26:49
HomeBox is a home inventory and organization system. Prior to 0.26.0, HandleWipeInventory in backend/app/api/handlers/v1/v1_ctrl_actions.go authorizes POST /v1/actions/wipe-inventory through the global ctx.User.IsOwner value instead of the caller's r...
CVE-2026-48974
- EPSS -
- Veröffentlicht 21.09.2026 17:42:59
- Zuletzt bearbeitet 29.09.2026 15:17:26
HomeBox is a home inventory and organization system. Prior to 0.26.0, POST /v1/groups/members invokes HandleGroupMemberAdd and GroupService.AddMember using a caller-supplied userID without requiring an owner role, an invitation token, target-user con...
CVE-2026-48975
- EPSS -
- Veröffentlicht 21.09.2026 17:42:14
- Zuletzt bearbeitet 23.09.2026 18:26:49
HomeBox is a home inventory and organization system. Prior to 0.26.0, MaintenanceEntryRepository.Update and MaintenanceEntryRepository.Delete in backend/internal/data/repo/repo_maintenance_entry.go use UpdateOneID(id) and DeleteOneID(id) without veri...
CVE-2026-48976
- EPSS -
- Veröffentlicht 21.09.2026 17:41:16
- Zuletzt bearbeitet 23.09.2026 18:26:49
HomeBox is a home inventory and organization system. Prior to 0.26.0, NotifierRepository.Update in backend/internal/data/repo/repo_notifier.go updates a notifier through UpdateOneID(id) without requiring the record's user ID to match the authenticate...
CVE-2026-40196
- EPSS 0.25%
- Veröffentlicht 17.04.2026 21:01:18
- Zuletzt bearbeitet 24.04.2026 14:23:38
HomeBox is a home inventory and organization system. Versions prior to 0.25.0 contain a vulnerability where the defaultGroup ID remained permanently assigned to a user after being invited to a group, even after their access to that group was revoked....
CVE-2026-27981
- EPSS 0.26%
- Veröffentlicht 03.03.2026 22:27:37
- Zuletzt bearbeitet 05.03.2026 17:56:43
HomeBox is a home inventory and organization system. Prior to 0.24.0, the authentication rate limiter (authRateLimiter) tracks failed attempts per client IP. It determines the client IP by reading, 1. X-Real-IP header, 2. First entry of X-Forwarded-F...
CVE-2026-27600
- EPSS 0.19%
- Veröffentlicht 03.03.2026 22:23:04
- Zuletzt bearbeitet 05.03.2026 21:15:49
HomeBox is a home inventory and organization system. Prior to 0.24.0-rc.1, the notifier functionality allows authenticated users to specify arbitrary URLs to which the application sends HTTP POST requests. No validation or restriction is applied to t...
CVE-2026-26272
- EPSS 0.17%
- Veröffentlicht 03.03.2026 22:20:32
- Zuletzt bearbeitet 05.03.2026 21:20:08
HomeBox is a home inventory and organization system. Prior to 0.24.0-rc.1, a stored cross-site scripting (XSS) vulnerability exists in the item attachment upload functionality. The application does not properly validate or restrict uploaded file type...