Home-assistant

Home-assistant

17 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.58%
  • Veröffentlicht 21.07.2026 15:39:52
  • Zuletzt bearbeitet 21.07.2026 20:28:41

Home Assistant Core before 2026.7.0 contains a path traversal vulnerability in the backup-restore function that allows attackers to write files to arbitrary absolute filesystem paths by supplying a crafted tar archive with a SYMTYPE entry containing ...

Medienbericht Exploit
  • EPSS 0.29%
  • Veröffentlicht 23.06.2026 18:18:08
  • Zuletzt bearbeitet 26.06.2026 20:17:26

Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2026.6.0, the Konnected integration registers an HTTP endpoint, KonnectedView (homeassistant/components/konnected/__init__.py), that is marked ...

Exploit
  • EPSS 0.2%
  • Veröffentlicht 27.03.2026 19:39:03
  • Zuletzt bearbeitet 31.03.2026 20:16:27

Home Assistant is open source home automation software that puts local control and privacy first. Starting in version 2025.02 and prior to version 2026.01 the "remaining charge time"-sensor for mobile phones (imported/included from Android Auto it ap...

Exploit
  • EPSS 0.24%
  • Veröffentlicht 27.03.2026 19:35:45
  • Zuletzt bearbeitet 31.03.2026 15:42:30

Home Assistant is open source home automation software that puts local control and privacy first. Starting in version 2020.02 and prior to version 2026.01, an authenticated party can add a malicious name to their device entity, allowing for Cross-Sit...

Exploit
  • EPSS 0.41%
  • Veröffentlicht 23.12.2025 00:00:00
  • Zuletzt bearbeitet 06.01.2026 17:27:46

Home Assistant Core before v2025.8.0 is vulnerable to Directory Traversal. The Downloader integration does not fully validate file paths during concatenation, leaving a path traversal vulnerability.

Exploit
  • EPSS 0.91%
  • Veröffentlicht 15.12.2023 03:15:45
  • Zuletzt bearbeitet 21.11.2024 08:37:11

Home Assistant is open source home automation software. Prior to version 2023.12.3, the login page discloses all active user accounts to any unauthenticated browsing request originating on the Local Area Network. Version 2023.12.3 contains a patch fo...

  • EPSS 0.42%
  • Veröffentlicht 20.10.2023 00:15:16
  • Zuletzt bearbeitet 21.11.2024 08:21:52

Home assistant is an open source home automation. The assessment verified that webhooks available in the webhook component are triggerable via the `*.ui.nabu.casa` URL without authentication, even when the webhook is marked as Only accessible from th...

  • EPSS 0.4%
  • Veröffentlicht 20.10.2023 00:15:16
  • Zuletzt bearbeitet 21.11.2024 08:21:52

Home assistant is an open source home automation. The audit team’s analyses confirmed that the `redirect_uri` and `client_id` are alterable when logging in. Consequently, the code parameter utilized to fetch the `access_token` post-authentication wil...

  • EPSS 0.46%
  • Veröffentlicht 19.10.2023 23:15:08
  • Zuletzt bearbeitet 21.11.2024 08:21:53

Home assistant is an open source home automation. In affected versions the `hassio.addon_stdin` is vulnerable to a partial Server-Side Request Forgery where an attacker capable of calling this service (e.g.: through GHSA-h2jp-7grc-9xpp) may be able t...

  • EPSS 0.95%
  • Veröffentlicht 19.10.2023 23:15:08
  • Zuletzt bearbeitet 21.11.2024 08:21:52

Home assistant is an open source home automation. Home Assistant server does not set any HTTP security headers, including the X-Frame-Options header, which specifies whether the web page is allowed to be framed. The omission of this and correlating h...