home-assistant
ICS / OT / IoToss-project
Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting home-assistant.
- CVE-2026-66061Home Assistant: iOS Companion app forwards NFC/QR tag scans without confirmation, enabling silent automation execution7.1
- CVE-2026-66060Home Assistant: Unconfirmed NFC/QR tag scans allow silent automation execution by untrusted callers7.1
- CVE-2026-59717Home Assistant Companion: `homeassistant://invite` Deep Link Credential Phishing4.3
- CVE-2026-64825Home Assistant Core < 2026.6.0 Path Traversal File Write via Backup Upload9.3
- CVE-2026-64824Home Assistant Core < 2026.7.0 Symlink Path Traversal RCE via backup-restore8.4
- CVE-2026-64823Home Assistant Core < 2026.5.4 XSS via Shelly media_player.py thumb URI4.7
- CVE-2026-55844Home Assistant: iOS Companion App ignores internal SSID allowlist for connections – possible leak of access token and sensor data7.5
- CVE-2026-54318Home Assistant: Exported BroadcastReceiver allows local apps to spoof device location7.1
- CVE-2026-54317Home Assistant: Konnected alarm-panel switch state and zone topology disclosed to unauthenticated actors on the LAN7.6
- CVE-2026-44698Home Assistant: Cross-origin iframe access token exfiltration via WebView JS bridge callback injection8.3
- CVE-2021-47942Home Assistant Community Store 1.10.0 Path Traversal Account Takeover7.5
- CVE-2026-34205Home Assistant: Unauthenticated App (Add-on) Endpoints Exposed to Local Network via Host Network Mode9.6
- CVE-2026-33045Home Assistant has stored XSS in history-graphs5.4
- CVE-2026-33044Home Assistant has stored XSS in Map-card through malicious device name5.4
- CVE-2025-65713Home Assistant Core before v2025.8.0 is vulnerable to Directory Traversal. The Downloader integration does not fully validate file paths during concatenation, leaving a path traversal vulnerability.4.0