Home Assistant is an open-source home-automation platform with a modestly represented vulnerability footprint across its core application, companion applications, and middleware components. The vendor's disclosures span a narrow but strategically important product set deployed in networked smart-home environments, and vulnerabilities merit attention primarily for their role in controlling connected devices and access to automation logic rather than for structural weakness patterns that recur across releases. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Home Assistant over time
Signals from CVEs in this vendor scope (19 CVEs).
19 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-27482CRITICAL homeassistant is an open source home automation tool. A remotely exploitable vulnerability bypassing authentication for accessing the Supervisor API through Home Assistant has been | Mar 8, 2023 | 10.0 | 79 | NO | YES |
CVE-2026-54317HIGH Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2026.6.0, the Konnected integration registers an HTTP endpoint, Konnected | Jun 23, 2026 | 7.6 | 34 | NO | NO |
CVE-2026-54318HIGH Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2026.5.3, the LocationSensorManager BroadcastReceiver is exported with no | Jun 23, 2026 | 7.1 | 31 | NO | NO |
CVE-2021-3152MEDIUM Home Assistant before 2021.1.3 does not have a protection layer that can help to prevent directory-traversal attacks against custom integrations. NOTE: the vendor's perspective is | Jan 26, 2021 | 5.3 | 29 | NO | YES |
CVE-2023-41897CRITICAL Home assistant is an open source home automation. Home Assistant server does not set any HTTP security headers, including the X-Frame-Options header, which specifies whether the we | Oct 19, 2023 | 9.6 | 26 | NO | NO |
CVE-2023-41895CRITICAL Home assistant is an open source home automation. The Home Assistant login page allows users to use their local Home Assistant credentials and log in to another website that specif | Oct 19, 2023 | 9.6 | 26 | NO | NO |
CVE-2020-36517HIGH An information leak in Nabu Casa Home Assistant Operating System and Home Assistant Supervised 2022.03 allows a DNS operator to gain knowledge about internal network resources via | Mar 10, 2022 | 7.5 | 26 | NO | NO |
CVE-2023-41896CRITICAL Home assistant is an open source home automation. Whilst auditing the frontend code to identify hidden parameters, Cure53 detected `auth_callback=1`, which is leveraged by the WebS | Oct 19, 2023 | 9.0 | 25 | NO | NO |
CVE-2023-44385HIGH The Home Assistant Companion for iOS and macOS app up to version 2023.4 are vulnerable to Client-Side Request Forgery. Attackers may send malicious links/QRs to victims that, when | Oct 19, 2023 | 8.8 | 24 | NO | NO |
CVE-2018-21019HIGH Home Assistant before 0.67.0 was vulnerable to an information disclosure that allowed an unauthenticated attacker to read the application's error log via components/api.py. | Sep 23, 2019 | 7.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (19 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Home Assistant.
Media articles that mention a CVE ID that affects a product developed by Home Assistant — matched by CVE ID, not by vendor name.