homeassistant has 9 CVEs on record between 2023 and 2026. 1 was published in the last 90 days. The median CVSS is 7.0 (high), with 1 rated critical. None have a confirmed exploitation report.
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.0
- Publish → KEV
- —
- Last 90 days
- 1 prev 3
Worst active — by depth score
CVE-2026-64825Critical· 9.3Home Assistant Core vulnerable to Path Traversal via backup upload during onboarding51CVE-2026-54317High· 7.6Home Assistant: Konnected alarm-panel switch state and zone topology disclosed to unauthenticated actors on the LAN42CVE-2025-62172HighHome Assistant has Stored XSS vulnerability in Energy dashboard from Energy Entity Name41CVE-2025-25305High· 7.0Home Assistant does not correctly validate SSL for outgoing requests in core and used libs39CVE-2025-65713MediumHome Assistant Core before is vulnerable to Directory Traversal28
homeassistant vulnerabilities
CVEs affecting homeassistant, newest first. Open any entry for full detail, references, and exploit status.
9 CVEsRSS
CVE-2026-64825Critical· 9.3Home Assistant Core vulnerable to Path Traversal via backup upload during onboarding
Home Assistant Core vulnerable to Path Traversal via backup upload during onboarding
CVE-2026-54317High· 7.6Home Assistant: Konnected alarm-panel switch state and zone topology disclosed to unauthenticated actors on the LAN
Home Assistant: Konnected alarm-panel switch state and zone topology disclosed to unauthenticated actors on the LAN
CVE-2026-33044LowHome Assistant has stored XSS in Map-card through malicious device name
Home Assistant has stored XSS in Map-card through malicious device name
CVE-2026-33045LowHome Assistant has stored XSS in history-graphs
Home Assistant has stored XSS in history-graphs
CVE-2025-65713MediumHome Assistant Core before is vulnerable to Directory Traversal
Home Assistant Core before is vulnerable to Directory Traversal
CVE-2025-62172HighHome Assistant has Stored XSS vulnerability in Energy dashboard from Energy Entity Name
Home Assistant has Stored XSS vulnerability in Energy dashboard from Energy Entity Name
CVE-2025-25305High· 7.0Home Assistant does not correctly validate SSL for outgoing requests in core and used libs
Home Assistant does not correctly validate SSL for outgoing requests in core and used libs
CVE-2023-50715Medium· 4.3User accounts disclosed to unauthenticated actors on the LAN
User accounts disclosed to unauthenticated actors on the LAN
CVE-2023-41893Medium· 4.3Home Assistant vulnerable to account takeover via auth_callback login
Home Assistant vulnerable to account takeover via auth_callback login