home assistant
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 17 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from February 18, 2025 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →Home Assistant Core < 2026.6.0 Path Traversal File Write via Backup Upload
Home Assistant Core < 2026.7.0 Symlink Path Traversal RCE via backup-restore
Home Assistant Core < 2026.5.4 XSS via Shelly media_player.py thumb URI
Home Assistant: iOS Companion App ignores internal SSID allowlist for connections – possible leak of access token and sensor data
Home Assistant: Exported BroadcastReceiver allows local apps to spoof device location
Home Assistant: Cross-origin iframe access token exfiltration via WebView JS bridge callback injection
Home Assistant Community Store 1.10.0 Path Traversal Account Takeover
Home Assistant: Unauthenticated App (Add-on) Endpoints Exposed to Local Network via Host Network Mode
Home Assistant has stored XSS in history-graphs
Home Assistant has stored XSS in Map-card through malicious device name
Monitor home assistant in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.