PT-2026-69134 · Home Assistant · Home Assistant Android Companion App
CVE-2026-59717
·
Published
2026-08-07
·
Updated
2026-08-07
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Home Assistant Android Companion app versions prior to 2026.6.1
Description
The Android Companion app contains an open redirect issue where the application processes the URL fragment from a
homeassistant://invite deep link during the onboarding flow without displaying the destination hostname. This allows an attacker to craft a malicious invitation that directs the user to a fraudulent /auth/authorize endpoint via a WebView. Because the server URL is not shown before the process is committed, users may be deceived into entering their credentials into a look-alike login page.Recommendations
Update to version 2026.6.1.
Exploit
Fix
Open Redirect
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Home Assistant Android Companion App