← Πίσω στην αναζήτηση CVE

CVE-2026-40602

Home Assistant

Περιγραφή

The Home Assistant Command-line interface (hass-cli) is a command-line tool for Home Assistant. Up to 1.0.0 of home-assitant-cli an unrestricted environment was used to handle Jninja2 templates instead of a sandboxed one. The user-supplied input within Jinja2 templates was rendered locally with no restrictions. This gave users access to Python-s internals and extended the scope of templating beyond the intended usage. This vulnerability is fixed in 1.0.0.

CVSS 5.6EPSS 0.10300000000000001%Κίνδυνος 0.57
Προβολή πηγής
Δημοσίευση
2026-04-21 18:16:51
Επηρεαζόμενες εκδόσεις
<1.0.0
Τύπος
Installed app
Διάνυσμα
CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:N