Home-assistant
Home-assistant Home Assistant: vulnerabilities and CVEs
Home-assistant Home Assistant has 9 published vulnerabilities, 9 of them in the last 12 months. 2 are rated critical and 0 are listed by CISA as actively exploited.
CVEs9
Last 12 months9
Critical2
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-91130 | Critical (9.3) | 0.39% | — | Sep 22, 2026 | Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.7.0, the Statistics Graph card in src/components/chart/statistics-chart.ts passed entity names through… |
| CVE-2026-91129 | Medium (5.4) | 0.20% | — | Sep 22, 2026 | Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.2.3, the IPP integration automatically processed unauthenticated _ipp._tcp.local mDNS announcements in… |
| CVE-2026-53458 | Medium (5.3) | 0.45% | — | Aug 18, 2026 | Blueprint Studio is a VS Code-like file editor for Home Assistant configuration files. Prior to 2.5.2, Blueprint Studio backend API handlers in custom_components/blueprint_studio/backend/api.py returned raw exception… |
| CVE-2026-53457 | Medium (5.1) | 0.76% | — | Aug 18, 2026 | Blueprint Studio is a VS Code-like file editor for Home Assistant configuration files. Prior to 2.5.2, the legacy stateless terminal command execution path in… |
| CVE-2026-53455 | High (8.6) | 0.50% | — | Aug 18, 2026 | Blueprint Studio is a VS Code-like file editor for Home Assistant configuration files. Prior to 2.5.2, Blueprint Studio generated a shell-based Git credential helper in… |
| CVE-2026-53453 | High (8.7) | 0.45% | — | Aug 18, 2026 | Blueprint Studio is a VS Code-like file editor for Home Assistant configuration files. Prior to 2.5.2, Blueprint Studio exposed administrator-intended backend API actions to any authenticated Home Assistant user because… |
| CVE-2026-44698 | High (8.3) | 0.17% | — | May 29, 2026 | Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2026.4.1 for iOS and 2026.4.4 for Android, he Home Assistant Companion apps for Android and iOS expose a… |
| CVE-2026-34205 | Critical (9.6) | 0.35% | — | Mar 27, 2026 | Home Assistant is open source home automation software that puts local control and privacy first. Home Assistant apps (formerly add-ons) configured with host network mode expose unauthenticated endpoints bound to the… |
| CVE-2025-62172 | High (8.5) | 0.42% | — | Oct 14, 2025 | Home Assistant is open source home automation software that puts local control and privacy first. In versions 2025.1.0 through 2025.10.1, the energy dashboard is vulnerable to stored cross-site scripting. An… |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.