Command-Line Tool Vulnerability in Home Assistant by Home Assistant Ecosystem
CVE-2026-40602

5.6MEDIUM

Key Information:

Vendor
CVE Published:
21 April 2026

What is CVE-2026-40602?

The Home Assistant CLI, a command-line tool for interfacing with Home Assistant, has a security issue where it utilizes an unrestricted environment for processing user-supplied Jinja2 templates. This flaw allows local rendering of templates without proper restrictions, enabling users to access Python's internals and misuse templating features beyond their designed purpose. The vulnerability has been addressed in version 1.0.0, ensuring enhanced safety for users.

Affected Version(s)

home-assistant-cli < 1.0.0

References

CVSS V3.1

Score:
5.6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.