CyberRota Analysis
AI-GeneratedHomeBox versions prior to 0.26.0 are vulnerable due to improper access control in the NotifierRepository.Update function, allowing authenticated users to manipulate notifiers belonging to other tenants. This could lead to unauthorized access to sensitive information, such as plaintext credentials for various notification services, and enable attackers to redirect notifications to their own endpoints. Organizations using HomeBox should prioritize upgrading to version 0.26.0 to mitigate these risks.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
HomeBox is a home inventory and organization system. Prior to 0.26.0, NotifierRepository.Update in backend/internal/data/repo/repo_notifier.go updates a notifier through UpdateOneID(id) without requiring the record's user ID to match the authenticated user. An authenticated user who supplies another tenant's notifier UUID to PUT /v1/notifiers/{id} can read the returned stored url, which may contain plaintext Shoutrrr credentials for Slack, SMTP, Telegram, Pushover, or Discord, and can replace the URL to redirect the victim's notifications to an attacker-controlled webhook. This issue is fixed in version 0.26.0.