Skip to main content

Vendor archive

home-assistant CVEs

Beta · best-effort

19 CVEs tagged to vendor home-assistant1 Critical, 11 High, 7 Medium, 0 Low, 0 Unrated.

CVE-2026-54318

Published Jun 23, 2026

Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2026.5.3, the LocationSensorManager BroadcastReceiver is exported with n…

CVSS 7.1 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-54317

Published Jun 23, 2026

Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2026.6.0, the Konnected integration registers an HTTP endpoint, Konnecte…

CVSS 7.6 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-33045

Published Mar 27, 2026

Home Assistant is open source home automation software that puts local control and privacy first. Starting in version 2025.02 and prior to version 2026.01 the "remaining charge ti…

CVSS 7.3 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-33044

Published Mar 27, 2026

Home Assistant is open source home automation software that puts local control and privacy first. Starting in version 2020.02 and prior to version 2026.01, an authenticated party…

CVSS 7.3 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-65713

Published Dec 23, 2025

Home Assistant Core before v2025.8.0 is vulnerable to Directory Traversal. The Downloader integration does not fully validate file paths during concatenation, leaving a path trave…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-50715

Published Dec 15, 2023

Home Assistant is open source home automation software. Prior to version 2023.12.3, the login page discloses all active user accounts to any unauthenticated browsing request origi…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-41894

Published Oct 20, 2023

Home assistant is an open source home automation. The assessment verified that webhooks available in the webhook component are triggerable via the `*.ui.nabu.casa` URL without aut…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-41893

Published Oct 20, 2023

Home assistant is an open source home automation. The audit team’s analyses confirmed that the `redirect_uri` and `client_id` are alterable when logging in. Consequently, the code…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-44385

Published Oct 19, 2023

The Home Assistant Companion for iOS and macOS app up to version 2023.4 are vulnerable to Client-Side Request Forgery. Attackers may send malicious links/QRs to victims that, when…

CVSS 8.6 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-41899

Published Oct 19, 2023

Home assistant is an open source home automation. In affected versions the `hassio.addon_stdin` is vulnerable to a partial Server-Side Request Forgery where an attacker capable of…

CVSS 6.6 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-41898

Published Oct 19, 2023

Home assistant is an open source home automation. The Home Assistant Companion for Android app up to version 2023.8.2 is vulnerable to arbitrary URL loading in a WebView. This ena…

CVSS 8.6 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-41897

Published Oct 19, 2023

Home assistant is an open source home automation. Home Assistant server does not set any HTTP security headers, including the X-Frame-Options header, which specifies whether the w…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-41895

Published Oct 19, 2023

Home assistant is an open source home automation. The Home Assistant login page allows users to use their local Home Assistant credentials and log in to another website that speci…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-36517

Published Mar 10, 2022

An information leak in Nabu Casa Home Assistant Operating System and Home Assistant Supervised 2022.03 allows a DNS operator to gain knowledge about internal network resources via…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-3152

Published Jan 26, 2021

Home Assistant before 2021.1.3 does not have a protection layer that can help to prevent directory-traversal attacks against custom integrations. NOTE: the vendor's perspective is…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-21019

Published Sep 23, 2019

Home Assistant before 0.67.0 was vulnerable to an information disclosure that allowed an unauthenticated attacker to read the application's error log via components/api.py.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-16782

Published Nov 10, 2017

In Home Assistant before 0.57, it is possible to inject JavaScript code into a persistent notification via crafted Markdown text, aka XSS.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-19 of 19 CVEsPage 1 of 1