Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
PYSEC-2026-3669
  • PyPI/homeassistant
Home Assistant Core vulnerable to Path Traversal via backup upload during onboarding 19 Aug
  • Fix available
  • Severity - 9.0 (Critical)
GHSA-5hxg-r395-fqxx
  • PyPI/homeassistant
Home Assistant Core vulnerable to Path Traversal via backup upload during onboarding 21 Jul
  • Fix available
  • Severity - 9.0 (Critical)
PYSEC-2026-2518
  • PyPI/homeassistant-cli
Home Assistant Command-line Interface: Handling of user-supplied Jinja2 templates 13 Jul
  • Fix available
  • Severity - 5.6 (Medium)
PYSEC-2026-2516
  • PyPI/homeassistant
Home Assistant has stored XSS in history-graphs 13 Jul
  • Fix available
  • Severity - 1.1 (Low)
PYSEC-2026-2517
  • PyPI/homeassistant
Home Assistant has stored XSS in Map-card through malicious device name 13 Jul
  • Fix available
  • Severity - 1.1 (Low)
PYSEC-2026-1454
  • PyPI/homeassistant
Home Assistant Core before is vulnerable to Directory Traversal 07 Jul
  • Fix available
  • Severity - 6.9 (Medium)
PYSEC-2026-1453
  • PyPI/homeassistant
Home Assistant has Stored XSS vulnerability in Energy dashboard from Energy Entity Name 07 Jul
  • Fix available
  • Severity - 8.5 (High)
PYSEC-2026-1452
  • PyPI/homeassistant
Home Assistant does not correctly validate SSL for outgoing requests in core and used libs 07 Jul
  • Fix available
  • Severity - 7.0 (High)
PYSEC-2026-1451
  • PyPI/homeassistant
User accounts disclosed to unauthenticated actors on the LAN 07 Jul
  • Fix available
  • Severity - 4.3 (Medium)
PYSEC-2026-241
  • PyPI/homeassistant
See record for full details 23 Jun
  • Fix available
  • Severity - 7.6 (High)
GHSA-x84v-g949-293w
  • PyPI/homeassistant
Home Assistant: Konnected alarm-panel switch state and zone topology disclosed to unauthenticated actors on the LAN 19 Jun
  • Fix available
  • Severity - 7.6 (High)
GHSA-33qf-q99x-wpm8
  • PyPI/homeassistant-cli
Home Assistant Command-line Interface: Handling of user-supplied Jinja2 templates 16 Apr
  • Fix available
  • Severity - 5.6 (Medium)
GHSA-46j8-vpx8-6p72
  • PyPI/homeassistant
Home Assistant has stored XSS in history-graphs 27 Mar
  • Fix available
  • Severity - 1.1 (Low)
GHSA-r584-6283-p7xc
  • PyPI/homeassistant
Home Assistant has stored XSS in Map-card through malicious device name 27 Mar
  • Fix available
  • Severity - 1.1 (Low)
GHSA-pp3g-xmm4-5cw9
  • PyPI/homeassistant
Home Assistant Core before is vulnerable to Directory Traversal 23 Dec 2025
  • Fix available
  • Severity - 6.9 (Medium)
GHSA-mq77-rv97-285m
  • PyPI/homeassistant
Home Assistant has Stored XSS vulnerability in Energy dashboard from Energy Entity Name 14 Oct 2025
  • Fix available
  • Severity - 8.5 (High)