Home Assistant AI maintains a focused vulnerability footprint centered on its Model Context Protocol (MCP) server component, which extends Home Assistant's integration and automation capabilities. This niche product scope and the absence of recurrent weakness patterns suggest a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Homeassistant Ai over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-32111MEDIUM ha-mcp is a Home Assistant MCP Server. Prior to 7.0.0, the ha-mcp OAuth consent form (beta feature) accepts a user-supplied ha_url and makes a server-side HTTP request to {ha_url}/ | Mar 11, 2026 | 5.3 | 20 | NO | NO |
CVE-2026-32112MEDIUM ha-mcp is a Home Assistant MCP Server. Prior to 7.0.0, the ha-mcp OAuth consent form renders user-controlled parameters via Python f-strings with no HTML escaping. An attacker who | Mar 11, 2026 | 4.7 | 19 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Homeassistant Ai.
Media articles that mention a CVE ID that affects a product developed by Homeassistant Ai — matched by CVE ID, not by vendor name.