PT-2025-41968 · Unknown · Home Assistant
Published
2025-10-14
·
Updated
2025-10-16
·
CVE-2025-62172
CVSS v4.0
9.3
Critical
| Vector | AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H |
Name of the Vulnerable Software and Affected Versions
Home Assistant versions 2025.1.0 through 2025.10.1
Description
Home Assistant is home automation software that prioritizes local control and privacy. The energy dashboard is susceptible to stored cross-site scripting. An authenticated user can inject malicious JavaScript code into an energy entity's name field. This code is then executed when any user hovers over data points in the energy dashboard graph tooltips. The issue occurs because entity names containing HTML are not properly sanitized before rendering in graph tooltips. This could allow an attacker with authentication to execute arbitrary JavaScript in the context of other users' sessions. If an energy provider supplies a malicious default name for an entity, the issue can be exploited without direct user action when the default name is used.
Recommendations
Update to Home Assistant version 2025.10.2.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Home Assistant