Open Redirect Vulnerability in Home Assistant Android Companion App
CVE-2026-59717
What is CVE-2026-59717?
The Home Assistant Android Companion App is susceptible to an open redirect vulnerability that can be exploited to mislead users during the onboarding process. Prior to the release of version 2026.6.1, the app allowed attackers to craft deceptive invitations, routing users to an unauthorized login page that mimicked the legitimate service. The flaw lies in the app passing the URL fragment from a homeassistant://invite deep link directly into the onboarding flow without displaying the true destination hostname to the user. This lack of transparency prevents victims from recognizing malicious attempts, ultimately enabling an easy credential theft method. Users are especially at risk as invitations generally target newcomers, making them less likely to notice the absence of a proper URL display before engaging with the potentially harmful interface.
Affected Version(s)
core < 2026.6.1
