pypi

homeassistant

View on pypi registry
22 Total advisories
22 Vulnerabilities
0 Malware

Dependency scanning

Check whether homeassistant is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Vulnerabilities

UNKNOWN
PyPI

CVE-2026-91130

Home Assistant: XSS in Statistics Graph Card

MEDIUM 5.4
PyPI

CVE-2026-91129

Home Assistant: mDNS Server-Side Request Forgery

MEDIUM 4.3
PyPI

CVE-2023-41893

Home Assistant vulnerable to account takeover via auth_callback login

CRITICAL 9.3
PyPI

CVE-2026-64825

Home Assistant Core vulnerable to Path Traversal via backup upload during onboarding

CRITICAL 9.3
PyPI

CVE-2026-64825

Home Assistant Core vulnerable to Path Traversal via backup upload during onboarding

HIGH 7.6
PyPI

CVE-2026-54317

Home Assistant: Konnected alarm-panel switch state and zone topology disclosed to unauthenticated actors on the LAN

UNKNOWN
PyPI

CVE-2026-33044

Home Assistant has stored XSS in Map-card through malicious device name

UNKNOWN
PyPI

CVE-2026-33045

Home Assistant has stored XSS in history-graphs

UNKNOWN
PyPI

CVE-2026-33045

Home Assistant has stored XSS in history-graphs

UNKNOWN
PyPI

CVE-2026-33044

Home Assistant has stored XSS in Map-card through malicious device name

UNKNOWN
PyPI

CVE-2025-62172

Home Assistant has Stored XSS vulnerability in Energy dashboard from Energy Entity Name

MEDIUM 4.3
PyPI

CVE-2023-50715

User accounts disclosed to unauthenticated actors on the LAN

HIGH 7.0
PyPI

CVE-2025-25305

Home Assistant does not correctly validate SSL for outgoing requests in core and used libs

UNKNOWN
PyPI

CVE-2025-65713

Home Assistant Core before is vulnerable to Directory Traversal

HIGH 7.0
PyPI

CVE-2025-25305

Home Assistant does not correctly validate SSL for outgoing requests in core and used libs

UNKNOWN
PyPI

CVE-2025-62172

Home Assistant has Stored XSS vulnerability in Energy dashboard from Energy Entity Name

MEDIUM 4.3
PyPI

CVE-2023-50715

User accounts disclosed to unauthenticated actors on the LAN

UNKNOWN
PyPI

CVE-2025-65713

Home Assistant Core before is vulnerable to Directory Traversal

HIGH 7.6
PyPI

CVE-2026-54317

CVE-2026-54317

UNKNOWN
PyPI

CVE-2018-21019

CVE-2018-21019

HIGH 7.5
PyPI

CVE-2018-21019

Home Assistant information disclosure vulnerability

MEDIUM 5.4
PyPI

CVE-2023-41893

CVE-2023-41893

Learn What is SAST?

Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →

Ready to move

Start Securing

Free, no credit card | First findings in minutes