← Retour à la recherche de CVE

CVE-2026-40602

Home Assistant

Description

The Home Assistant Command-line interface (hass-cli) is a command-line tool for Home Assistant. Up to 1.0.0 of home-assitant-cli an unrestricted environment was used to handle Jninja2 templates instead of a sandboxed one. The user-supplied input within Jinja2 templates was rendered locally with no restrictions. This gave users access to Python-s internals and extended the scope of templating beyond the intended usage. This vulnerability is fixed in 1.0.0.

CVSS 5.6EPSS 0.10300000000000001%Risque 0.57
Voir la source
Publication
2026-04-21 18:16:51
Versions concernées
<1.0.0
Type
Installed app
Vecteur
CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:N