homeassistant
PyPI12 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting homeassistantpage 1 of 1
- CVE-2018-21019HIGHCVSS 7.5EG 7.5fixed in 0.67.02019-09-23
vulnerable: 0.10.0 ... 0.9.1 (188 versions)
Home Assistant before 0.67.0 was vulnerable to an information disclosure that allowed an unauthenticated attacker to read the application's error log via components/api.py.
- CVE-2023-41893MEDIUMCVSS 5.4EG 5.4fixed in 2023.9.02023-10-20
vulnerable: 0.10.0 ... 2023.9.0b6 (1132 versions)
Home assistant is an open source home automation. The audit team’s analyses confirmed that the `redirect_uri` and `client_id` are alterable when logging in. Consequently, the code parameter utilized to fetch the `access_token` post-authe…
- CVE-2023-50715MEDIUMCVSS 4.3EG 4.3fixed in 2023.12.32023-12-15
vulnerable: 0.10.0 ... 2023.9.3 (1170 versions)
Home Assistant is open source home automation software. Prior to version 2023.12.3, the login page discloses all active user accounts to any unauthenticated browsing request originating on the Local Area Network. Version 2023.12.3 contains…
- CVE-2025-25305HIGHCVSS 7.0EG 7.0fixed in 2024.1.62025-02-18
vulnerable: 0.10.0 ... 2024.1.5 (1187 versions)
Home Assistant Core is an open source home automation that puts local control and privacy first. Affected versions are subject to a potential man-in-the-middle attacks due to missing SSL certificate verification in the project codebase and…
- CVE-2025-62172HIGHCVSS 8.5EG 8.5fixed in 2025.10.22025-10-14
vulnerable: 2025.1.0 ... 2025.9.4 (134 versions)
Home Assistant is open source home automation software that puts local control and privacy first. In versions 2025.1.0 through 2025.10.1, the energy dashboard is vulnerable to stored cross-site scripting. An authenticated user can inject m…
- CVE-2025-65713MEDIUMCVSS 4.0EG 4.0fixed in 2025.8.02025-12-23
vulnerable: 0.10.0 ... 2025.8.0b5 (1468 versions)
Home Assistant Core before v2025.8.0 is vulnerable to Directory Traversal. The Downloader integration does not fully validate file paths during concatenation, leaving a path traversal vulnerability.
- CVE-2026-33044MEDIUMCVSS 5.4EG 5.4fixed in 2026.012026-03-27
vulnerable: 2020.12.0 ... 2026.1.0b5 (851 versions)
Home Assistant is open source home automation software that puts local control and privacy first. Starting in version 2020.02 and prior to version 2026.01, an authenticated party can add a malicious name to their device entity, allowing fo…
- CVE-2026-33045MEDIUMCVSS 5.4EG 5.4fixed in 2026.012026-03-27
vulnerable: 2025.10.0 ... 2026.1.0b5 (152 versions)
Home Assistant is open source home automation software that puts local control and privacy first. Starting in version 2025.02 and prior to version 2026.01 the "remaining charge time"-sensor for mobile phones (imported/included from Android…
- CVE-2026-54317HIGHCVSS 7.6EG 7.6fixed in 2026.6.02026-06-19
vulnerable: 0.10.0 ... 2026.6.0b4 (1583 versions)
Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2026.6.0, the Konnected integration registers an HTTP endpoint, KonnectedView (homeassistant/components/konnected/__init__.py), that…
- CVE-2026-64825CRITICALCVSS 9.3EG 9.3fixed in 2026.6.02026-07-21
vulnerable: 0.10.0 ... 2026.6.0b4 (1583 versions)
Home Assistant Core before 2026.6.0 contains a path traversal vulnerability that allows unauthenticated attackers to write arbitrary files to any directory on the host filesystem by uploading a crafted backup archive during the initial onb…
- CVE-2026-91129MEDIUMCVSS 5.4EG 5.4fixed in 2026.2.32026-09-22
vulnerable: 0.10.0 ... 2026.2.2 (1542 versions)
Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.2.3, the IPP integration automatically processed unauthenticated _ipp._tcp.local mDNS announcements in homeassistant/components/ipp/…
- CVE-2026-91130CRITICALCVSS 9.3EG 9.3fixed in 2026.7.02026-09-22
vulnerable: 0.10.0 ... 2026.7.0b4 (1593 versions)
Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.7.0, the Statistics Graph card in src/components/chart/statistics-chart.ts passed entity names through getStatisticLabel and compute…
Check whether homeassistant is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for homeassistant CVEs against the assets you own.
Book a Demo →