PT-2026-97016 · Unknown · Home Assistant

CVE-2026-91130

·

Published

2026-09-22

·

Updated

2026-09-23

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions Home Assistant versions prior to 2026.7.0
Description An authenticated user or a malicious integration provider can execute a Cross-Site Scripting (XSS) attack against users who view a Statistics Graph card. The issue occurs because the statistics-chart component interpolates the param.seriesName variable into the ECharts tooltip HTML without proper escaping or using the filterXSS() function. This allows script-related HTML to execute when a viewer hovers over a data point on a Line chart. The vulnerability affects the Mean, State, Sum, and Change fields, but does not affect Bar charts. The data flow involves the getStatisticLabel() and computeStateName() functions in src/components/chart/statistics-chart.ts and src/common/entity/compute state name.ts. A supply-chain vector exists where an integration that automatically names entities could deliver the payload without requiring the attacker to have an account on the target instance.
Recommendations Update Home Assistant to version 2026.7.0.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-91130
GHSA-WX4M-69M9-GX3M

Affected Products

Home Assistant