homeassistant vulnerabilities
CVEs whose affected-version data names the homeassistant package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
9 CVEsRSS
CVE-2026-64825Critical· 9.3Home Assistant Core vulnerable to Path Traversal via backup upload during onboarding
Home Assistant Core vulnerable to Path Traversal via backup upload during onboarding
CVE-2026-54317High· 7.6Home Assistant: Konnected alarm-panel switch state and zone topology disclosed to unauthenticated actors on the LAN
Home Assistant: Konnected alarm-panel switch state and zone topology disclosed to unauthenticated actors on the LAN
CVE-2026-33044LowHome Assistant has stored XSS in Map-card through malicious device name
Home Assistant has stored XSS in Map-card through malicious device name
CVE-2026-33045LowHome Assistant has stored XSS in history-graphs
Home Assistant has stored XSS in history-graphs
CVE-2025-65713MediumHome Assistant Core before is vulnerable to Directory Traversal
Home Assistant Core before is vulnerable to Directory Traversal
CVE-2025-62172HighHome Assistant has Stored XSS vulnerability in Energy dashboard from Energy Entity Name
Home Assistant has Stored XSS vulnerability in Energy dashboard from Energy Entity Name
CVE-2025-25305High· 7.0Home Assistant does not correctly validate SSL for outgoing requests in core and used libs
Home Assistant does not correctly validate SSL for outgoing requests in core and used libs
CVE-2023-50715Medium· 4.3User accounts disclosed to unauthenticated actors on the LAN
User accounts disclosed to unauthenticated actors on the LAN
CVE-2023-41893Medium· 4.3Home Assistant vulnerable to account takeover via auth_callback login
Home Assistant vulnerable to account takeover via auth_callback login