Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-40602

20
FAUCET Score

BRIEFING NOTE: CVE-2026-40602 OVERVIEW Home Assistant Command-line Interface (hass-cli) versions up to 1.0.0 contain a template injection vulnerability in Jinja2 template processing. The vulnerability stems from the use of an unrestricted rendering environment instead of a sandboxed one, allowing user-supplied input within Jinja2 templates to be processed without restrictions and providing access to Python's internal functions and objects. SEVERITY The vulnerability carries a CVSS v3.1 score of 5.6 (MEDIUM) with a local attack vector, high attack complexity, and high privileges required. Exploitation requires user interaction. While the confidentiality and integrity impacts are rated high, there is no availability impact. The EPSS score of 0.00018 indicates this vulnerability has a very low probability of exploitation in the wild compared to other CVEs. EXPLOITATION STATUS There is no evidence of active exploitation. The vulnerability is not listed on CISA's Known Exploited Vulnerabilities catalog, and community attention remains minimal, reflected in its inactive status on vulnerability tracking lists. The moderate FAUCET Risk Score of 33.0/100 suggests limited real-world threat potential, likely due to the requirement for local access and user interaction to trigger the vulnerability.

Impacted Technologies

VendorProductVersion(s)CPE
< 1.0.0CPE matchmatch criteria
cpe:2.3:a:home-assistant-ecosystem:home_assistant_command-line_interface:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.6MEDIUM

CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:N

Attack Vector
LOCAL
Attack Complexity
HIGH
Privileges Required
HIGH
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
NONE
Exploitability Score
0.3
Impact Score
5.2
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.10%
Probability of exploitation in next 30 days
EPSS Percentile
1.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0010 is in the 11th percentile among its peer group of 74 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

pippatch availablevia ghsa
Product: homeassistant-cliFixed in: 1.0.0
github_advisoryworkaround availablevia nvd_reference
View patch

Vendor Advisories (1)

pipGHSA-33qf-q99x-wpm8medium

Home Assistant Command-line Interface: Handling of user-supplied Jinja2 templates

Apr 16, 2026

References

github.com / home-assistant-ecosystem/home-assistant-cli/pull/453
Issue Tracking
github.com / home-assistant-ecosystem/home-assistant-cli/security/advisories/GHSA-33qf-q99x-wpm8
MitigationVendor Advisory