Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

home-assistant — Vulnerabilities & Security Advisories 26

Browse all 26 CVE security advisories affecting home-assistant. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Home Assistant serves as an open-source home automation platform integrating IoT devices and smart home systems. Historically, it has faced vulnerabilities including remote code execution, cross-site scripting, privilege escalation, and authentication bypass issues. The platform's 15 recorded CVEs highlight risks in its web interface, API endpoints, and third-party integrations. Notable security characteristics include its Python-based architecture and extensive community-developed components, which introduce potential supply chain risks. While no major public security incidents have been widely documented, the consistent discovery of vulnerabilities underscores the importance of regular updates and secure configuration for deployments handling sensitive home systems.

CVE ID Title CVSS Severity Published
CVE-2026-66061 Home Assistant: iOS Companion app forwards NFC/QR tag scans without confirmation, enabling silent automation execution — core CWE-862 7.1 High 2026-08-07
CVE-2026-66060 Home Assistant: Unconfirmed NFC/QR tag scans allow silent automation execution by untrusted callers — core CWE-862 7.1 High 2026-08-07
CVE-2026-59717 Home Assistant Companion: `homeassistant://invite` Deep Link Credential Phishing — core CWE-601 4.3 Medium 2026-08-07
CVE-2026-64825 Home Assistant Core < 2026.6.0 Path Traversal File Write via Backup Upload — Home Assistant Core CWE-22 9.3 Critical 2026-07-21
CVE-2026-64824 Home Assistant Core < 2026.7.0 Symlink Path Traversal RCE via backup-restore — Home Assistant Core CWE-22 8.4 High 2026-07-21
CVE-2026-64823 Home Assistant Core < 2026.5.4 XSS via Shelly media_player.py thumb URI — Home Assistant Core CWE-79 4.7 Medium 2026-07-21
CVE-2026-55844 Home Assistant: iOS Companion App ignores internal SSID allowlist for connections – possible leak of access token and sensor data — core CWE-319 7.5 High 2026-06-29
CVE-2026-54318 Home Assistant: Exported BroadcastReceiver allows local apps to spoof device location — core CWE-926 7.1 High 2026-06-23
CVE-2026-54317 Home Assistant: Konnected alarm-panel switch state and zone topology disclosed to unauthenticated actors on the LAN — core CWE-200 7.6 High 2026-06-23
CVE-2026-44698 Home Assistant: Cross-origin iframe access token exfiltration via WebView JS bridge callback injection — core CWE-94 8.3 High 2026-05-29
CVE-2021-47942 Home Assistant Community Store 1.10.0 Path Traversal Account Takeover — Home Assistant Community Store (HACS) CWE-22 7.5 High 2026-05-16
CVE-2026-34205 Home Assistant: Unauthenticated App (Add-on) Endpoints Exposed to Local Network via Host Network Mode — Home Assistant Operating System CWE-923 9.7 Critical 2026-03-27
CVE-2026-33045 Home Assistant has stored XSS in history-graphs — core CWE-79 6.1 - 2026-03-27
CVE-2026-33044 Home Assistant has stored XSS in Map-card through malicious device name — core CWE-79 5.4 - 2026-03-27
CVE-2025-62172 Home Assistant vulnerable to Stored XSS in Energy dashboard from Energy Entity Name — core CWE-80 5.4AI Medium AI 2025-10-14
CVE-2025-25305 SSL validation for outgoing requests in Home Assistant Core and used libs not correct — core CWE-940 7.0 High 2025-02-18
CVE-2023-50715 User accounts disclosed to unauthenticated actors on the LAN — core CWE-200 4.3 Medium 2023-12-15
CVE-2023-41893 Account takeover via auth_callback login in Home Assistant Core — core CWE-200 4.3 Medium 2023-10-19
CVE-2023-41894 Local-only webhooks externally accessible via SniTun in Home Assistant Core — core CWE-669 5.3 Medium 2023-10-19
CVE-2023-41895 Cross-site Scripting via auth_callback login in Home Assistant Core — core CWE-79 8.8 High 2023-10-19
CVE-2023-41896 Fake websocket server installation permits full takeover in Home Assistant Core — core CWE-345 7.1 High 2023-10-19
CVE-2023-41897 Lack of XFO header allows clickjacking in Home Assistant Core — core CWE-1021 8.8 High 2023-10-19
CVE-2023-41899 Partial Server-Side Request Forgery in Home Assistant Core — core CWE-918 6.6 Medium 2023-10-19
CVE-2023-41898 Arbitrary URL load in Android WebView in `MyActivity.kt` in Home Assistant Companion for Android — core CWE-345 8.6 High 2023-10-19
CVE-2023-44385 Client-Side Request Forgery in Home Assistant iOS/macOS native Apps — core CWE-352 8.6 High 2023-10-19
CVE-2023-27482 Home Assistant 授权问题漏洞 — core CWE-287 10.0 Critical 2023-03-08

This page lists every published CVE security advisory associated with home-assistant. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.