CVE Tools

Home-assistant

8 CVEs tracked since 2023. Since Oct 2023, none of them reached CISA KEV.

Home-assistant CVEs per month

Oct 2023 to Oct 2023. Point at a month, or focus the strip and use the arrow keys.
Home-assistant CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2023-1080

Products

The products that kept showing up in Home-assistant's monthly top three, with their CVEs summed over those months.

  1. Core81 month
  2. Home-assistant61 month
  3. Home Assistant Companion21 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Home-assistant.

  1. CVE-2026-91129Home Assistant: mDNS Server-Side Request Forgery5.4
  2. CVE-2026-91130Home Assistant: XSS in Statistics Graph Card—
  3. CVE-2026-66061Home Assistant: iOS Companion app forwards NFC/QR tag scans without confirmation, enabling silent automation execution7.1
  4. CVE-2026-66060Home Assistant: Unconfirmed NFC/QR tag scans allow silent automation execution by untrusted callers7.1
  5. CVE-2026-59717Home Assistant Companion: `homeassistant://invite` Deep Link Credential Phishing4.3
  6. CVE-2026-64825Home Assistant Core < 2026.6.0 Path Traversal File Write via Backup Upload9.3
  7. CVE-2026-64824Home Assistant Core < 2026.7.0 Symlink Path Traversal RCE via backup-restore8.4
  8. CVE-2026-64823Home Assistant Core < 2026.5.4 XSS via Shelly media_player.py thumb URI4.7
  9. CVE-2026-55844Home Assistant: iOS Companion App ignores internal SSID allowlist for connections – possible leak of access token and sensor data7.5
  10. CVE-2026-54318Home Assistant: Exported BroadcastReceiver allows local apps to spoof device location7.1
  11. CVE-2026-54317Home Assistant: Konnected alarm-panel switch state and zone topology disclosed to unauthenticated actors on the LAN7.6
  12. CVE-2026-44698Home Assistant: Cross-origin iframe access token exfiltration via WebView JS bridge callback injection8.3
  13. CVE-2021-47942Home Assistant Community Store 1.10.0 Path Traversal Account Takeover7.5
  14. CVE-2026-34205Home Assistant: Unauthenticated App (Add-on) Endpoints Exposed to Local Network via Host Network Mode9.6
  15. CVE-2026-33045Home Assistant has stored XSS in history-graphs5.4

The record

Peak rank
#95 in Oct 2023
Busiest month shown
Oct 2023, 8 CVEs
Months with a KEV entry
0 since Oct 2023
Monthly snapshots
1 since 2023
Home-assistant's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store