BRIEFING NOTE: CVE-2026-40602 OVERVIEW Home Assistant Command-line Interface (hass-cli) versions up to 1.0.0 contain a template injection vulnerability in Jinja2 template processing. The vulnerability stems from the use of an unrestricted rendering environment instead of a sandboxed one, allowing user-supplied input within Jinja2 templates to be processed without restrictions and providing access to Python's internal functions and objects. SEVERITY The vulnerability carries a CVSS v3.1 score of 5.6 (MEDIUM) with a local attack vector, high attack complexity, and high privileges required. Exploitation requires user interaction. While the confidentiality and integrity impacts are rated high, there is no availability impact. The EPSS score of 0.00018 indicates this vulnerability has a very low probability of exploitation in the wild compared to other CVEs. EXPLOITATION STATUS There is no evidence of active exploitation. The vulnerability is not listed on CISA's Known Exploited Vulnerabilities catalog, and community attention remains minimal, reflected in its inactive status on vulnerability tracking lists. The moderate FAUCET Risk Score of 33.0/100 suggests limited real-world threat potential, likely due to the requirement for local access and user interaction to trigger the vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.0.0CPE matchmatch criteria | cpe:2.3:a:home-assistant-ecosystem:home_assistant_command-line_interface:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.