An authenticated user can submit a crafted notifier through POST /v1/notifiers or POST /v1/notifiers/test, potentially disclosing retrieved metadata such as temporary credentials on a Homebox instance that egresses through NAT64/DNS64. This medium-severity vulnerability affects Homebox instances with notifier features in use, particularly those with NAT64/DNS64 egress configurations. Defenders should asse [truncated]
CVE-2026-48974 is a vulnerability in HomeBox, a home inventory and organization system, prior to version 0.26.0. The vulnerability allows any authenticated user to force another account into the caller's group, disclose the target user's email address and name, and create a membership prerequisite for a separate cross-group inventory-wipe vulnerability. This issue is fixed in version 0.26.0.