VulnSea

homeassistant vulnerabilities

CVEs whose affected-version data names the homeassistant package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

9 CVEsRSS

CVE-2026-64825Critical· 9.3
2mo ago

Home Assistant Core vulnerable to Path Traversal via backup upload during onboarding

Home Assistant Core vulnerable to Path Traversal via backup upload during onboarding

Midnighthomeassistant · homeassistantEPSS 0.58%via OSV
CVE-2026-54317High· 7.6
3mo ago

Home Assistant: Konnected alarm-panel switch state and zone topology disclosed to unauthenticated actors on the LAN

Home Assistant: Konnected alarm-panel switch state and zone topology disclosed to unauthenticated actors on the LAN

Twilighthomeassistant · homeassistantEPSS 0.31%via GHSA
CVE-2026-33044Low
5mo ago

Home Assistant has stored XSS in Map-card through malicious device name

Home Assistant has stored XSS in Map-card through malicious device name

Sunlithomeassistant · homeassistantEPSS 0.22%via OSV
CVE-2026-33045Low
5mo ago

Home Assistant has stored XSS in history-graphs

Home Assistant has stored XSS in history-graphs

Sunlithomeassistant · homeassistantEPSS 0.20%via OSV
CVE-2025-65713Medium
9mo ago

Home Assistant Core before is vulnerable to Directory Traversal

Home Assistant Core before is vulnerable to Directory Traversal

Sunlithomeassistant · homeassistantEPSS 0.40%via OSV
CVE-2025-62172High
11mo ago

Home Assistant has Stored XSS vulnerability in Energy dashboard from Energy Entity Name

Home Assistant has Stored XSS vulnerability in Energy dashboard from Energy Entity Name

Twilighthomeassistant · homeassistantEPSS 0.42%via OSV
CVE-2025-25305High· 7.0
1y ago

Home Assistant does not correctly validate SSL for outgoing requests in core and used libs

Home Assistant does not correctly validate SSL for outgoing requests in core and used libs

Twilighthomeassistant · homeassistantEPSS 0.25%via OSV
CVE-2023-50715Medium· 4.3
2y ago

User accounts disclosed to unauthenticated actors on the LAN

User accounts disclosed to unauthenticated actors on the LAN

Sunlithomeassistant · homeassistantEPSS 0.91%via OSV
CVE-2023-41893Medium· 4.3
2y ago

Home Assistant vulnerable to account takeover via auth_callback login

Home Assistant vulnerable to account takeover via auth_callback login

Sunlithomeassistant · homeassistantEPSS 0.40%via OSV
homeassistant vulnerabilities (CVEs) · VulnSea