PT-2026-69134 · Home Assistant · Home Assistant Android Companion App

CVE-2026-59717

·

Published

2026-08-07

·

Updated

2026-08-07

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Home Assistant Android Companion app versions prior to 2026.6.1
Description The Android Companion app contains an open redirect issue where the application processes the URL fragment from a homeassistant://invite deep link during the onboarding flow without displaying the destination hostname. This allows an attacker to craft a malicious invitation that directs the user to a fraudulent /auth/authorize endpoint via a WebView. Because the server URL is not shown before the process is committed, users may be deceived into entering their credentials into a look-alike login page.
Recommendations Update to version 2026.6.1.

Exploit

Fix

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-59717
GHSA-68F4-97MF-F68W

Affected Products

Home Assistant Android Companion App