Vulnerabilidades em home-assistant
28 resultadosAnálise Vexday
Home Assistant apresenta 19 vulnerabilidades catalogadas, predominantemente do tipo XSS (CWE-79), com 2 casos críticos e nenhuma sob exploração ativa conhecida. O ritmo recente de 4 divulgações nos últimos 90 dias indica evolução contínua da superfície de ataque, exigindo atenção especial em controles de entrada e sanitização de dados.
CVE-2025-25305HIGHSSL validation for outgoing requests in Home Assistant Core and used libs not correctEPSS 0.3%CVE-2026-33045HIGHHome Assistant has stored XSS in history-graphsEPSS 0.2%CVE-2026-91129MEDIUMHome Assistant: mDNS Server-Side Request ForgeryEPSS 0.2%CVE-2026-54318HIGHHome Assistant: Exported BroadcastReceiver allows local apps to spoof device locationEPSS 0.2%CVE-2026-66060HIGHHome Assistant: Unconfirmed NFC/QR tag scans allow silent automation execution by untrusted callersEPSS 0.2%CVE-2026-66061HIGHHome Assistant: iOS Companion app forwards NFC/QR tag scans without confirmation, enabling silent automation executionEPSS 0.2%CVE-2026-44698HIGHHome Assistant: Cross-origin iframe access token exfiltration via WebView JS bridge callback injectionEPSS 0.2%CVE-2023-41898HIGH Arbitrary URL load in Android WebView in `MyActivity.kt` in Home Assistant Companion for AndroidEPSS 0.2%