← Voltar à pesquisa de CVEs

CVE-2026-40602

Home Assistant

Descrição

The Home Assistant Command-line interface (hass-cli) is a command-line tool for Home Assistant. Up to 1.0.0 of home-assitant-cli an unrestricted environment was used to handle Jninja2 templates instead of a sandboxed one. The user-supplied input within Jinja2 templates was rendered locally with no restrictions. This gave users access to Python-s internals and extended the scope of templating beyond the intended usage. This vulnerability is fixed in 1.0.0.

CVSS 5.6EPSS 0.10300000000000001%Risco 0.57
Ver fonte
Publicação
2026-04-21 18:16:51
Versões afetadas
<1.0.0
Tipo
Installed app
Vetor
CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:N