home assistant
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 22 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from February 18, 2025 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →Blueprint Studio API authorization bypass for non-admin Home Assistant users
ZDI-26-560: (Pwn2Own) Home Assistant Green go2rtc Command Injection Remote Code Execution Vulnerability
ZDI-26-562: (Pwn2Own) Home Assistant Green mDNS Server-Side Request Forgery Vulnerability
Home Assistant: Unconfirmed NFC/QR tag scans allow silent automation execution by untrusted callers
Home Assistant Companion: `homeassistant://invite` Deep Link Credential Phishing
Home Assistant Core < 2026.6.0 Path Traversal File Write via Backup Upload
Home Assistant Core < 2026.7.0 Symlink Path Traversal RCE via backup-restore
Home Assistant Core < 2026.5.4 XSS via Shelly media_player.py thumb URI
Home Assistant: iOS Companion App ignores internal SSID allowlist for connections – possible leak of access token and sensor data
Home Assistant: Exported BroadcastReceiver allows local apps to spoof device location
Monitor home assistant in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.