HTML Injection Vulnerability in Home Assistant Automation Software
CVE-2026-91130
9.3CRITICAL
What is CVE-2026-91130?
Home Assistant, the open-source home automation platform, had a vulnerability in its Statistics Graph card prior to version 2026.7.0. This flaw allowed potentially malicious HTML to execute when an authenticated user hovered over data points on a line chart. The issue stemmed from the improper handling of entity names in tooltip HTML generated by ECharts. Specifically, the inability to escape user inputs resulted in script execution vulnerabilities affecting the default Line chart configuration, with Bar charts remaining unaffected. This critical issue emphasizes the importance of software updates to safeguard against such security risks.
Affected Version(s)
core < 2026.7.0
