Dependency scanning
Check whether homeassistant is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
CVE-2026-91130
Home Assistant: XSS in Statistics Graph Card
CVE-2026-91129
Home Assistant: mDNS Server-Side Request Forgery
CVE-2023-41893
Home Assistant vulnerable to account takeover via auth_callback login
CVE-2026-64825
Home Assistant Core vulnerable to Path Traversal via backup upload during onboarding
CVE-2026-64825
Home Assistant Core vulnerable to Path Traversal via backup upload during onboarding
CVE-2026-54317
Home Assistant: Konnected alarm-panel switch state and zone topology disclosed to unauthenticated actors on the LAN
CVE-2026-33044
Home Assistant has stored XSS in Map-card through malicious device name
CVE-2026-33045
Home Assistant has stored XSS in history-graphs
CVE-2026-33045
Home Assistant has stored XSS in history-graphs
CVE-2026-33044
Home Assistant has stored XSS in Map-card through malicious device name
CVE-2025-62172
Home Assistant has Stored XSS vulnerability in Energy dashboard from Energy Entity Name
CVE-2023-50715
User accounts disclosed to unauthenticated actors on the LAN
CVE-2025-25305
Home Assistant does not correctly validate SSL for outgoing requests in core and used libs
CVE-2025-65713
Home Assistant Core before is vulnerable to Directory Traversal
CVE-2025-25305
Home Assistant does not correctly validate SSL for outgoing requests in core and used libs
CVE-2025-62172
Home Assistant has Stored XSS vulnerability in Energy dashboard from Energy Entity Name
CVE-2023-50715
User accounts disclosed to unauthenticated actors on the LAN
CVE-2025-65713
Home Assistant Core before is vulnerable to Directory Traversal
CVE-2026-54317
CVE-2026-54317
CVE-2018-21019
CVE-2018-21019
CVE-2018-21019
Home Assistant information disclosure vulnerability
CVE-2023-41893
CVE-2023-41893
Browse more PyPI advisories
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes