HTML Injection Vulnerability in Home Assistant Automation Software
CVE-2026-91130

9.3CRITICAL

Key Information:

Status
Vendor
CVE Published:
22 September 2026

What is CVE-2026-91130?

Home Assistant, the open-source home automation platform, had a vulnerability in its Statistics Graph card prior to version 2026.7.0. This flaw allowed potentially malicious HTML to execute when an authenticated user hovered over data points on a line chart. The issue stemmed from the improper handling of entity names in tooltip HTML generated by ECharts. Specifically, the inability to escape user inputs resulted in script execution vulnerabilities affecting the default Line chart configuration, with Bar charts remaining unaffected. This critical issue emphasizes the importance of software updates to safeguard against such security risks.

Affected Version(s)

core < 2026.7.0

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.