Command-Line Tool Vulnerability in Home Assistant by Home Assistant Ecosystem
CVE-2026-40602
5.6MEDIUM
What is CVE-2026-40602?
The Home Assistant CLI, a command-line tool for interfacing with Home Assistant, has a security issue where it utilizes an unrestricted environment for processing user-supplied Jinja2 templates. This flaw allows local rendering of templates without proper restrictions, enabling users to access Python's internals and misuse templating features beyond their designed purpose. The vulnerability has been addressed in version 1.0.0, ensuring enhanced safety for users.
Affected Version(s)
home-assistant-cli < 1.0.0
