CVE-2026-91130Critical· 9.3▾ AbyssalPoC availableHome Assistant is open source home automation software focused on local control and privacy. Prior to 2026.7.0, the Statistics Graph card in src/components/chart/statistics-chart.ts passed entity names through getStatisticLabel and compu…
▾ Abyssal zone — Critical with a public exploit or in-the-wild use
impact 51.2 · likelihood 0.1 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake. The CVSS score shown above comes from the assigning CNA record, not NVD.
Exploit-prediction probability, daily snapshots since Sep 23.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.5%
Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.7.0, the Statistics Graph card in src/components/chart/statistics-chart.ts passed entity names through getStatisticLabel and computeStateName and interpolated param.seriesName into ECharts tooltip HTML without escaping. An authenticated user or an integration that supplies a malicious default entity name could cause script-related HTML to execute when a viewer hovered over a data point. Mean, State, Sum, and Change fields in the default Line chart configuration were affected, while Bar charts were not. This issue is fixed in version 2026.7.0.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
homeassistant < 2026.7.0Patched in:
homeassistant 2026.7.0Connected by shared product, vendor, weakness, or advisory.
CVE-2023-41893Medium· 4.3Home Assistant vulnerable to account takeover via auth_callback login
CVE-2026-64825Critical· 9.3Home Assistant Core vulnerable to Path Traversal via backup upload during onboarding
CVE-2026-33044LowHome Assistant has stored XSS in Map-card through malicious device name
CVE-2025-65713MediumHome Assistant Core before is vulnerable to Directory Traversal
CVE-2025-62172HighHome Assistant has Stored XSS vulnerability in Energy dashboard from Energy Entity Name
CVE-2025-25305High· 7.0Home Assistant does not correctly validate SSL for outgoing requests in core and used libs