Vulnerabilidades en home-assistant
26 resultadosAnálisis Vexday
Home Assistant apresenta 19 vulnerabilidades catalogadas, predominantemente do tipo XSS (CWE-79), com 2 casos críticos e nenhuma sob exploração ativa conhecida. O ritmo recente de 4 divulgações nos últimos 90 dias indica evolução contínua da superfície de ataque, exigindo atenção especial em controles de entrada e sanitização de dados.
CVE-2023-41898HIGH Arbitrary URL load in Android WebView in `MyActivity.kt` in Home Assistant Companion for AndroidEPSS 0.2%CVE-2026-55844HIGHHome Assistant: iOS Companion App ignores internal SSID allowlist for connections – possible leak of access token and sensor dataEPSS 0.2%CVE-2026-54318HIGHHome Assistant: Exported BroadcastReceiver allows local apps to spoof device locationEPSS 0.1%CVE-2026-44698HIGHHome Assistant: Cross-origin iframe access token exfiltration via WebView JS bridge callback injectionEPSS 0.1%CVE-2026-66060HIGHHome Assistant: Unconfirmed NFC/QR tag scans allow silent automation execution by untrusted callersEPSS 0.1%CVE-2026-66061HIGHHome Assistant: iOS Companion app forwards NFC/QR tag scans without confirmation, enabling silent automation executionEPSS 0.1%