CVE-2025-64759: Homarr is Vulnerable to Stored Cross-Site Scripting (XSS) and Possible Privilege Escalation via Malicious SVG Upload
Homarr is an open-source dashboard. Prior to version 1.43.3, stored XSS vulnerability exists, allowing the execution of arbitrary JavaScript in a user's browser, with minimal or no user interaction required, due to the rendering of a malicious uploaded SVG file. This could be abused to add an attacker's account to the "credentials-admin" group, giving them full administrative access, if a user logged in as an administrator was to view the page which renders or redirects to the SVG. This issue has been patched in version 1.43.3.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-64759?
CVE-2025-64759 has a high severity level due to its potential for stored XSS attacks allowing execution of malicious scripts.
How do I fix CVE-2025-64759?
To fix CVE-2025-64759, you should upgrade Homarr to version 1.43.3 or later.
What type of vulnerability is CVE-2025-64759?
CVE-2025-64759 is a stored Cross-Site Scripting (XSS) vulnerability.
What versions of Homarr are affected by CVE-2025-64759?
CVE-2025-64759 affects all versions of Homarr prior to version 1.43.3.
What are the potential impacts of CVE-2025-64759?
CVE-2025-64759 could allow attackers to execute arbitrary JavaScript in the browser of a user with minimal interaction.