OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-91130

CRITICAL · CVSS 9.3 EPSS 0.39% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-22 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

The Statistics Graph card in Home Assistant prior to version 2026.7.0 is vulnerable to cross-site scripting (XSS) due to improper handling of entity names in ECharts tooltips, allowing an authenticated user or malicious integration to execute arbitrary HTML when hovering over data points. This critical vulnerability (CVSS 9.3) could lead to unauthorized actions or data exposure within the application. Users and administrators of Home Assistant should prioritize upgrading to version 2026.7.0 to mitigate this risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-91130
Severity
CRITICAL
CVSS
9.3
EPSS
0.39%

Original NVD Description

Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.7.0, the Statistics Graph card in src/components/chart/statistics-chart.ts passed entity names through getStatisticLabel and computeStateName and interpolated param.seriesName into ECharts tooltip HTML without escaping. An authenticated user or an integration that supplies a malicious default entity name could cause script-related HTML to execute when a viewer hovered over a data point. Mean, State, Sum, and Change fields in the default Line chart configuration were affected, while Bar charts were not. This issue is fixed in version 2026.7.0.