PT-2025-41968 · Unknown · Home Assistant

Published

2025-10-14

·

Updated

2025-10-16

·

CVE-2025-62172

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions Home Assistant versions 2025.1.0 through 2025.10.1
Description Home Assistant is home automation software that prioritizes local control and privacy. The energy dashboard is susceptible to stored cross-site scripting. An authenticated user can inject malicious JavaScript code into an energy entity's name field. This code is then executed when any user hovers over data points in the energy dashboard graph tooltips. The issue occurs because entity names containing HTML are not properly sanitized before rendering in graph tooltips. This could allow an attacker with authentication to execute arbitrary JavaScript in the context of other users' sessions. If an energy provider supplies a malicious default name for an entity, the issue can be exploited without direct user action when the default name is used.
Recommendations Update to Home Assistant version 2025.10.2.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-62172
GHSA-MQ77-RV97-285M

Affected Products

Home Assistant