Descripción
HomeBox is a home inventory and organization system. Versions prior to 0.25.0 contain a vulnerability where the defaultGroup ID remained permanently assigned to a user after being invited to a group, even after their access to that group was revoked. While the web interface correctly enforced the access revocation and prevented the user from viewing or modifying the group-s contents, the API did not. Because the original group ID persisted as the user-s defaultGroup, and this value was not properly validated when the X-Tenant header was omitted, the user could still perform full CRUD operations on the group-s collections through the API, bypassing the intended access controls. This issue has been fixed in version 0.25.0.
CVSS 8.1EPSS 0.247%Riesgo 0.83
Ver fuente- Publicación
- 2026-04-17 21:16:33
- Versiones afectadas
- <0.25.0
- Tipo
- Installed app
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N