VulnSea

homeassistant has 9 CVEs on record between 2023 and 2026. 1 was published in the last 90 days. The median CVSS is 7.0 (high), with 1 rated critical. None have a confirmed exploitation report.

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.0
Publish → KEV
Last 90 days
1 prev 3

Weakness classes

Products

  • homeassistant 9
9
Total CVEs
1
Critical
0
CISA KEV
0
Exploited

homeassistant vulnerabilities

CVEs affecting homeassistant, newest first. Open any entry for full detail, references, and exploit status.

9 CVEsRSS

CVE-2026-64825Critical· 9.3
2mo ago

Home Assistant Core vulnerable to Path Traversal via backup upload during onboarding

Home Assistant Core vulnerable to Path Traversal via backup upload during onboarding

Midnighthomeassistant · homeassistantEPSS 0.58%via OSV
CVE-2026-54317High· 7.6
3mo ago

Home Assistant: Konnected alarm-panel switch state and zone topology disclosed to unauthenticated actors on the LAN

Home Assistant: Konnected alarm-panel switch state and zone topology disclosed to unauthenticated actors on the LAN

Twilighthomeassistant · homeassistantEPSS 0.31%via GHSA
CVE-2026-33044Low
5mo ago

Home Assistant has stored XSS in Map-card through malicious device name

Home Assistant has stored XSS in Map-card through malicious device name

Sunlithomeassistant · homeassistantEPSS 0.22%via OSV
CVE-2026-33045Low
5mo ago

Home Assistant has stored XSS in history-graphs

Home Assistant has stored XSS in history-graphs

Sunlithomeassistant · homeassistantEPSS 0.20%via OSV
CVE-2025-65713Medium
9mo ago

Home Assistant Core before is vulnerable to Directory Traversal

Home Assistant Core before is vulnerable to Directory Traversal

Sunlithomeassistant · homeassistantEPSS 0.40%via OSV
CVE-2025-62172High
11mo ago

Home Assistant has Stored XSS vulnerability in Energy dashboard from Energy Entity Name

Home Assistant has Stored XSS vulnerability in Energy dashboard from Energy Entity Name

Twilighthomeassistant · homeassistantEPSS 0.42%via OSV
CVE-2025-25305High· 7.0
1y ago

Home Assistant does not correctly validate SSL for outgoing requests in core and used libs

Home Assistant does not correctly validate SSL for outgoing requests in core and used libs

Twilighthomeassistant · homeassistantEPSS 0.25%via OSV
CVE-2023-50715Medium· 4.3
2y ago

User accounts disclosed to unauthenticated actors on the LAN

User accounts disclosed to unauthenticated actors on the LAN

Sunlithomeassistant · homeassistantEPSS 0.91%via OSV
CVE-2023-41893Medium· 4.3
2y ago

Home Assistant vulnerable to account takeover via auth_callback login

Home Assistant vulnerable to account takeover via auth_callback login

Sunlithomeassistant · homeassistantEPSS 0.40%via OSV
homeassistant vulnerabilities (CVEs) · VulnSea