Uh oh!
There was an error while loading.Please reload this page.
- Notifications
You must be signed in to change notification settings - Fork36.2k
Security: home-assistant/core
Security
- Stored XSS in graph tooltip from entity nameGHSA-mq77-rv97-285m published
Oct 14, 2025 bybramkragtenHigh - SSL validation for outgoing requests in core and used libs not correctGHSA-m3pm-rpgg-5wj6 published
Feb 18, 2025 byMartinHjelmareHigh - User accounts disclosed to unauthenticated actors on the LANGHSA-jqpc-rc7g-vf83 published
Dec 14, 2023 byfrenckModerate - Account takeover via auth_callback loginGHSA-qhhj-7hrc-gqj5 published
Oct 19, 2023 byfrenckLow - Full takeover via javascript URI in auth_callback loginGHSA-jvxq-x42r-f7mv published
Oct 19, 2023 byfrenckCritical - Local-only webhooks externally accessible via SniTunGHSA-wx3j-3v2j-rf45 published
Oct 19, 2023 byfrenckLow - Fake WS server installation permits full takeoverGHSA-cr83-q7r2-7f5q published
Oct 19, 2023 byfrenckCritical - Lack of XFO header allows clickjackingGHSA-935v-rmg9-44mw published
Oct 19, 2023 byfrenckCritical - Actions expression injection in `helpers/version/action.yml`GHSA-jff5-5j3g-vhqc published
Oct 19, 2023 byfrenckLow - Arbitrary URL load in Android WebView in `MyActivity.kt`GHSA-jvpm-q3hq-86rg published
Oct 19, 2023 byfrenckHigh
Learn more about advisories related tohome-assistant/core in theGitHub Advisory Database