{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/home-assistant--2026.7.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:home-assistant:home_assistant:*:*:*:*:*:*:*:*"],"_cs_cves":[{"id":"CVE-2026-91130"},{"id":"CVE-2025-62172"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Home Assistant (\u003c 2026.7.0)"],"_cs_severities":["critical"],"_cs_tags":["xss","web-vulnerability","supply-chain"],"_cs_type":"advisory","_cs_vendors":["Home Assistant"],"content_html":"\u003cp\u003eHome Assistant versions prior to 2026.7.0 are vulnerable to a stored Cross-Site Scripting (XSS) attack via the Statistics Graph card component. The vulnerability exists because the application fails to sanitize entity names before rendering them within ECharts tooltips. Specifically, in \u003ccode\u003esrc/components/chart/statistics-chart.ts\u003c/code\u003e, the \u003ccode\u003eparam.seriesName\u003c/code\u003e variable is interpolated into an HTML string without being passed through the \u003ccode\u003efilterXSS()\u003c/code\u003e function. This oversight mirrors a similar vulnerability found in the Energy dashboard (CVE-2025-62172), which was previously patched. An attacker can exploit this by setting a malicious name for an entity, either as an authenticated user or through a supply-chain vector via a third-party integration that automatically populates entity names. When an unsuspecting user views a Statistics Graph card containing the compromised entity and hovers over a data point, the malicious JavaScript executes in their browser session.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn attacker identifies a target Home Assistant instance or a third-party integration utilized by target users.\u003c/li\u003e\n\u003cli\u003eThe attacker crafts a payload containing malicious HTML/JavaScript within an entity name string (e.g., \u003ccode\u003e\u0026lt;img src=x onerror=alert(document.domain) /\u0026gt;\u003c/code\u003e).\u003c/li\u003e\n\u003cli\u003eIf via supply chain, the attacker compromises a third-party integration or uses a malicious integration to inject the payload into the Home Assistant entity database.\u003c/li\u003e\n\u003cli\u003eIf via direct access, an authenticated attacker creates a \u0026quot;Template sensor\u0026quot; helper with the malicious name.\u003c/li\u003e\n\u003cli\u003eThe target user adds a Statistics Graph card to their dashboard, configured to display the malicious entity.\u003c/li\u003e\n\u003cli\u003eThe victim navigates to the dashboard and interacts with the chart by hovering over a data point.\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003estatistics-chart\u003c/code\u003e component renders the unsanitized entity name into the ECharts tooltip, triggering the malicious script execution.\u003c/li\u003e\n\u003cli\u003eThe script executes within the context of the victim's authenticated browser session, leading to potential account compromise or further actions.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability allows for remote code execution within the victim's browser context. If exploited via the supply-chain vector, an attacker does not require direct access to the target's Home Assistant instance to deliver the payload. Successful exploitation grants the attacker the ability to perform actions on behalf of the authenticated user, potentially leading to unauthorized control over smart home devices, exfiltration of configuration data, or further internal network reconnaissance.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for administrators:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade Home Assistant to version 2026.7.0 or later immediately to patch CVE-2026-91130.\u003c/li\u003e\n\u003cli\u003eReview all third-party integrations and custom sensors for unexpected or anomalous entity names.\u003c/li\u003e\n\u003cli\u003eAudit existing dashboard Statistics Graph cards for any entities displaying irregular naming conventions.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-23T01:54:10Z","date_published":"2026-09-23T01:54:10Z","id":"https://feed.craftedsignal.io/briefs/2026-09-home-assistant-xss/","summary":"Home Assistant contains a stored Cross-Site Scripting (XSS) vulnerability (CVE-2026-91130) in the Statistics Graph card, allowing arbitrary JavaScript execution when viewing entities with malicious names.","title":"Stored XSS in Home Assistant Statistics Graph Card","url":"https://feed.craftedsignal.io/briefs/2026-09-home-assistant-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - Home Assistant (\u003c 2026.7.0)","version":"https://jsonfeed.org/version/1.1"}