PT-2026-97016 · Unknown · Home Assistant
CVE-2026-91130
·
Published
2026-09-22
·
Updated
2026-09-23
CVSS v4.0
9.3
Critical
| Vector | AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H |
Name of the Vulnerable Software and Affected Versions
Home Assistant versions prior to 2026.7.0
Description
An authenticated user or a malicious integration provider can execute a Cross-Site Scripting (XSS) attack against users who view a Statistics Graph card. The issue occurs because the
statistics-chart component interpolates the param.seriesName variable into the ECharts tooltip HTML without proper escaping or using the filterXSS() function. This allows script-related HTML to execute when a viewer hovers over a data point on a Line chart. The vulnerability affects the Mean, State, Sum, and Change fields, but does not affect Bar charts. The data flow involves the getStatisticLabel() and computeStateName() functions in src/components/chart/statistics-chart.ts and src/common/entity/compute state name.ts. A supply-chain vector exists where an integration that automatically names entities could deliver the payload without requiring the attacker to have an account on the target instance.Recommendations
Update Home Assistant to version 2026.7.0.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Home Assistant