CVE-2023-41897 is a critical clickjacking vulnerability affecting Home Assistant, an open-source home automation platform. The absence of HTTP security headers, particularly X-Frame-Options, allows attackers to embed Home Assistant within malicious frames. This flaw carries a CVSS score of 9.6 (Critical) due to its potential for remote code execution (RCE) with minimal user interaction, as attackers can trick users into installing malicious add-ons. While there is no evidence of active exploitation or public exploit code, and community discussion is minimal, all users are strongly advised to upgrade to version 2023.9.0 or later to mitigate this significant risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2023.9.0CPE matchmatch criteria | cpe:2.3:a:home-assistant:home-assistant:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.8 Bluesky, 0.5 Mastodon, and 1.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.