ha-mcp
PyPI2 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting ha-mcppage 1 of 1
- CVE-2026-32111MEDIUMCVSS 5.3EG 5.3✓ Fixed in 7.0.02026-03-11
vulnerable: 3.3.0 ... 6.7.2 (85 versions)
ha-mcp is a Home Assistant MCP Server. Prior to 7.0.0, the ha-mcp OAuth consent form (beta feature) accepts a user-supplied ha_url and makes a server-side HTTP request to {ha_url}/api/config with no URL validation. An unauthenticated attac…
- CVE-2026-32112MEDIUMCVSS 4.7EG 4.7✓ Fixed in 7.0.02026-03-11
vulnerable: 3.3.0 ... 6.7.2 (85 versions)
ha-mcp is a Home Assistant MCP Server. Prior to 7.0.0, the ha-mcp OAuth consent form renders user-controlled parameters via Python f-strings with no HTML escaping. An attacker who can reach the OAuth endpoint and convince the server operat…
Check whether ha-mcp is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for ha-mcp CVEs against the assets you own.
Start Free Scan →