CVE-2026-91130: CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) in home-assistant core
Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.7.0, the Statistics Graph card in src/components/chart/statistics-chart.ts passed entity names through getStatisticLabel and computeStateName and interpolated param.seriesName into ECharts tooltip HTML without escaping. An authenticated user or an integration that supplies a malicious default entity name could cause script-related HTML to execute when a viewer hovered over a data point. Mean, State, Sum, and Change fields in the default Line chart configuration were affected, while Bar charts were not. This issue is fixed in version 2026.7.0.
AI Analysis
Technical Summary
Home Assistant core versions before 2026.7.0 contain an improper neutralization of script-related HTML tags (CWE-80) in the Statistics Graph card component. Specifically, entity names passed through getStatisticLabel and computeStateName are interpolated into ECharts tooltip HTML without proper escaping. This allows an authenticated user or integration that can supply a malicious default entity name to execute script code when a viewer hovers over a data point in affected Line charts (Mean, State, Sum, Change fields). Bar charts are not affected. The vulnerability is addressed in version 2026.7.0.
Potential Impact
An attacker with authenticated access or control over an integration can inject malicious script code that executes in the context of the viewer's browser when hovering over certain data points in the Statistics Graph card. This can lead to cross-site scripting attacks with high impact as indicated by the CVSS 9.3 score, potentially compromising confidentiality, integrity, and availability of the affected system or user session.
Mitigation Recommendations
Upgrade Home Assistant core to version 2026.7.0 or later, where this vulnerability is fixed. No other mitigation or temporary workaround is indicated. Users should ensure they apply this official fix to prevent exploitation.
CVE-2026-91130: CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) in home-assistant core
Description
Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.7.0, the Statistics Graph card in src/components/chart/statistics-chart.ts passed entity names through getStatisticLabel and computeStateName and interpolated param.seriesName into ECharts tooltip HTML without escaping. An authenticated user or an integration that supplies a malicious default entity name could cause script-related HTML to execute when a viewer hovered over a data point. Mean, State, Sum, and Change fields in the default Line chart configuration were affected, while Bar charts were not. This issue is fixed in version 2026.7.0.
CVSS v4.0
Score 9.3critical
Affected software
home-assistant
core
pkg:github/home-assistant/coreRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Home Assistant core versions before 2026.7.0 contain an improper neutralization of script-related HTML tags (CWE-80) in the Statistics Graph card component. Specifically, entity names passed through getStatisticLabel and computeStateName are interpolated into ECharts tooltip HTML without proper escaping. This allows an authenticated user or integration that can supply a malicious default entity name to execute script code when a viewer hovers over a data point in affected Line charts (Mean, State, Sum, Change fields). Bar charts are not affected. The vulnerability is addressed in version 2026.7.0.
Potential Impact
An attacker with authenticated access or control over an integration can inject malicious script code that executes in the context of the viewer's browser when hovering over certain data points in the Statistics Graph card. This can lead to cross-site scripting attacks with high impact as indicated by the CVSS 9.3 score, potentially compromising confidentiality, integrity, and availability of the affected system or user session.
Mitigation Recommendations
Upgrade Home Assistant core to version 2026.7.0 or later, where this vulnerability is fixed. No other mitigation or temporary workaround is indicated. Users should ensure they apply this official fix to prevent exploitation.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-09-14T19:36:48.844Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6ab2d481f7a7c54106a364d0
Added to database: 09/22/2026, 19:18:25 UTC
Last enriched: 09/22/2026, 19:32:42 UTC
Last updated: 09/23/2026, 01:58:06 UTC
Views: 10
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.