| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-wx4m-69m9-gx3m | Home Assistant: XSS in Statistics Graph Card |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 22 Sep 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Home-assistant
Home-assistant core |
|
| Vendors & Products |
Home-assistant
Home-assistant core |
Tue, 22 Sep 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 22 Sep 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.7.0, the Statistics Graph card in src/components/chart/statistics-chart.ts passed entity names through getStatisticLabel and computeStateName and interpolated param.seriesName into ECharts tooltip HTML without escaping. An authenticated user or an integration that supplies a malicious default entity name could cause script-related HTML to execute when a viewer hovered over a data point. Mean, State, Sum, and Change fields in the default Line chart configuration were affected, while Bar charts were not. This issue is fixed in version 2026.7.0. | |
| Title | Home Assistant: XSS in Statistics Graph Card | |
| Weaknesses | CWE-80 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-22T19:41:01.261Z
Reserved: 2026-09-14T19:36:48.844Z
Link: CVE-2026-91130
Updated: 2026-09-22T19:40:07.560Z
Status : Received
Published: 2026-09-22T19:16:56.700
Modified: 2026-09-22T20:17:11.607
Link: CVE-2026-91130
No data.
OpenCVE Enrichment
Updated: 2026-09-22T21:15:07Z
Github GHSA