« Back to list

Home-assistant

Home-assistant Home Assistant: vulnerabilities and CVEs

Home-assistant Home Assistant has 9 published vulnerabilities, 9 of them in the last 12 months. 2 are rated critical and 0 are listed by CISA as actively exploited.

CVEs9
Last 12 months9
Critical2
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-91130Critical (9.3)0.39%—Sep 22, 2026
Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.7.0, the Statistics Graph card in src/components/chart/statistics-chart.ts passed entity names through…
CVE-2026-91129Medium (5.4)0.20%—Sep 22, 2026
Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.2.3, the IPP integration automatically processed unauthenticated _ipp._tcp.local mDNS announcements in…
CVE-2026-53458Medium (5.3)0.45%—Aug 18, 2026
Blueprint Studio is a VS Code-like file editor for Home Assistant configuration files. Prior to 2.5.2, Blueprint Studio backend API handlers in custom_components/blueprint_studio/backend/api.py returned raw exception…
CVE-2026-53457Medium (5.1)0.76%—Aug 18, 2026
Blueprint Studio is a VS Code-like file editor for Home Assistant configuration files. Prior to 2.5.2, the legacy stateless terminal command execution path in…
CVE-2026-53455High (8.6)0.50%—Aug 18, 2026
Blueprint Studio is a VS Code-like file editor for Home Assistant configuration files. Prior to 2.5.2, Blueprint Studio generated a shell-based Git credential helper in…
CVE-2026-53453High (8.7)0.45%—Aug 18, 2026
Blueprint Studio is a VS Code-like file editor for Home Assistant configuration files. Prior to 2.5.2, Blueprint Studio exposed administrator-intended backend API actions to any authenticated Home Assistant user because…
CVE-2026-44698High (8.3)0.17%—May 29, 2026
Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2026.4.1 for iOS and 2026.4.4 for Android, he Home Assistant Companion apps for Android and iOS expose a…
CVE-2026-34205Critical (9.6)0.35%—Mar 27, 2026
Home Assistant is open source home automation software that puts local control and privacy first. Home Assistant apps (formerly add-ons) configured with host network mode expose unauthenticated endpoints bound to the…
CVE-2025-62172High (8.5)0.42%—Oct 14, 2025
Home Assistant is open source home automation software that puts local control and privacy first. In versions 2025.1.0 through 2025.10.1, the energy dashboard is vulnerable to stored cross-site scripting. An…

🎯 How it gets exploited (ATT&CK techniques)

  1. T1210 Exploitation of Remote Services4
  2. T1059.007 JavaScript3
  3. T1189 Drive-by Compromise2
  4. T1059 Command and Scripting Interpreter1
  5. T1078.001 Default Accounts1
  6. T1090.001 Internal Proxy1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Home-assistant