Vulnerabilidades en home-assistant

28 resultados
Análisis Vexday

Home Assistant apresenta 19 vulnerabilidades catalogadas, predominantemente do tipo XSS (CWE-79), com 2 casos críticos e nenhuma sob exploração ativa conhecida. O ritmo recente de 4 divulgações nos últimos 90 dias indica evolução contínua da superfície de ataque, exigindo atenção especial em controles de entrada e sanitização de dados.

CVE-2023-27482CRITICALhomeassistant is an open source home automation tool. A remotely exploitable vulnerability bypassing authentication for accessing the SupervEPSS 72.2%CVE-2023-41897HIGHLack of XFO header allows clickjacking in Home Assistant CoreEPSS 0.9%CVE-2023-50715MEDIUMUser accounts disclosed to unauthenticated actors on the LANEPSS 0.9%CVE-2026-64824CRITICALHome Assistant Core < 2026.7.0 Symlink Path Traversal RCE via backup-restoreEPSS 0.8%CVE-2023-41895HIGHCross-site Scripting via auth_callback login in Home Assistant CoreEPSS 0.7%CVE-2026-64825CRITICALHome Assistant Core < 2026.6.0 Path Traversal File Write via Backup UploadEPSS 0.6%CVE-2021-47942HIGHHome Assistant Community Store 1.10.0 Path Traversal Account TakeoverEPSS 0.5%CVE-2023-41899MEDIUMPartial Server-Side Request Forgery in Home Assistant Core EPSS 0.5%CVE-2023-41894MEDIUMLocal-only webhooks externally accessible via SniTun in Home Assistant CoreEPSS 0.4%CVE-2025-62172HIGHHome Assistant vulnerable to Stored XSS in Energy dashboard from Energy Entity NameEPSS 0.4%CVE-2023-41893MEDIUMAccount takeover via auth_callback login in Home Assistant CoreEPSS 0.4%CVE-2026-91130CRITICALHome Assistant: XSS in Statistics Graph CardEPSS 0.4%CVE-2026-59717MEDIUMHome Assistant Companion: `homeassistant://invite` Deep Link Credential PhishingEPSS 0.4%CVE-2026-34205CRITICALHome Assistant: Unauthenticated App (Add-on) Endpoints Exposed to Local Network via Host Network ModeEPSS 0.3%CVE-2026-54317HIGHHome Assistant: Konnected alarm-panel switch state and zone topology disclosed to unauthenticated actors on the LANEPSS 0.3%CVE-2026-64823LOWHome Assistant Core < 2026.5.4 XSS via Shelly media_player.py thumb URIEPSS 0.3%CVE-2023-44385HIGHClient-Side Request Forgery in Home Assistant iOS/macOS native AppsEPSS 0.3%CVE-2026-33044HIGHHome Assistant has stored XSS in Map-card through malicious device nameEPSS 0.3%CVE-2023-41896HIGHFake websocket server installation permits full takeover in Home Assistant CoreEPSS 0.3%CVE-2026-55844HIGHHome Assistant: iOS Companion App ignores internal SSID allowlist for connections – possible leak of access token and sensor dataEPSS 0.3%