vciy

CVEs we hold for Home-assistant

Records whose assigning authority named Home-assistant as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-66061Home Assistant: iOS Companion app forwards NFC/QR tag scans without confirmation, enabling silent automation executionhome-assistant core
CVE-2026-66060Home Assistant: Unconfirmed NFC/QR tag scans allow silent automation execution by untrusted callershome-assistant core
CVE-2026-64825Home Assistant Core < 2026.6.0 Path Traversal File Write via Backup Uploadhome-assistant Home Assistant Core
CVE-2026-64824Home Assistant Core < 2026.7.0 Symlink Path Traversal RCE via backup-restorehome-assistant Home Assistant Core
CVE-2026-64823Home Assistant Core < 2026.5.4 XSS via Shelly media_player.py thumb URIhome-assistant Home Assistant Core
CVE-2026-59717Home Assistant Companion: `homeassistant://invite` Deep Link Credential Phishinghome-assistant core
CVE-2026-55844Home Assistant: iOS Companion App ignores internal SSID allowlist for connections – possible leak of access token and…home-assistant core
CVE-2026-54318Home Assistant: Exported BroadcastReceiver allows local apps to spoof device locationhome-assistant core
CVE-2026-54317Home Assistant: Konnected alarm-panel switch state and zone topology disclosed to unauthenticated actors on the LANhome-assistant core
CVE-2026-44698Home Assistant: Cross-origin iframe access token exfiltration via WebView JS bridge callback injectionhome-assistant core; Home Assistant Companion app (iOS)…
CVE-2026-40602hass-cli: Handling of user-supplied Jinja2 templateshome-assistant-ecosystem home-assistant-cli
CVE-2026-34205Home Assistant: Unauthenticated App (Add-on) Endpoints Exposed to Local Network via Host Network Modehome-assistant Home Assistant Supervisor
CVE-2026-33045Home Assistant has stored XSS in history-graphshome-assistant core
CVE-2026-33044Home Assistant has stored XSS in Map-card through malicious device namehome-assistant core
CVE-2025-62172Home Assistant vulnerable to Stored XSS in Energy dashboard from Energy Entity Namehome-assistant core
CVE-2025-25305SSL validation for outgoing requests in Home Assistant Core and used libs not correcthome-assistant core
CVE-2023-50715User accounts disclosed to unauthenticated actors on the LANhome-assistant core
CVE-2023-44385Client-Side Request Forgery in Home Assistant iOS/macOS native Appshome-assistant core
CVE-2023-41899Partial Server-Side Request Forgery in Home Assistant Corehome-assistant core
CVE-2023-41898Arbitrary URL load in Android WebView in `MyActivity.kt` in Home Assistant Companion for Androidhome-assistant core
CVE-2023-41897Lack of XFO header allows clickjacking in Home Assistant Corehome-assistant core
CVE-2023-41896Fake websocket server installation permits full takeover in Home Assistant Corehome-assistant core
CVE-2023-41895Cross-site Scripting via auth_callback login in Home Assistant Corehome-assistant core
CVE-2023-41894Local-only webhooks externally accessible via SniTun in Home Assistant Corehome-assistant core
CVE-2023-41893Account takeover via auth_callback login in Home Assistant Corehome-assistant core
CVE-2023-27482no title heldhome-assistant supervisor
CVE-2021-47942Home Assistant Community Store 1.10.0 Path Traversal Account TakeoverHome-Assistant Home Assistant Community Store (HACS)

27 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.