External risk intelligence

Home Assistant Statistics Graph Card HTML Injection Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-91130

Home Assistant is often deployed for local home automation and frequently kept on internal networks. While it can be exposed to the internet for remote access, this is a secondary configuration rather than a universal requirement. The vulnerability requires an authenticated user or integration to trigger, which further limits the likelihood of public internet-facing exploitation.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This vulnerability affects Home Assistant, an open-source home automation software, allowing an authenticated user to execute script-related HTML through a specific chart card when a viewer hovers over a data point. The primary concern is confirming if this specific functionality is used and if any malicious default entity names are present.

  • Malicious HTML can run via a Home Assistant chart.
  • It matters if users interact with specific chart data.
  • Confirm usage and exposure of the affected feature.

Attack Path

How an attacker could exploit the issue

An attacker with existing authenticated access to Home Assistant could craft a malicious default entity name. When another user views a statistics graph containing this entity, hovering over a data point would trigger script execution within their browser. This could allow an attacker to compromise the session of the user viewing the graph.

  • Requires authenticated user access.
  • Triggered by viewing a crafted statistics graph.
  • Leads to script execution in the browser.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an authenticated user or integration to execute arbitrary HTML and script code within the Home Assistant frontend. When a user hovers over a data point in a statistics graph, malicious script embedded in an entity name could execute. This is possible when the Statistics Graph card is used with default Line chart configurations for Mean, State, Sum, or Change fields.

  • System data and user interface are at risk.
  • Malicious script executes on hover.
  • Could lead to unauthorized actions or data leakage.

Operational Fix

Recommended remediation, mitigation, and detection steps

The Home Assistant platform team, alongside application owners, should coordinate efforts to address this vulnerability. The first practical step involves identifying all Home Assistant instances, confirming their exposure and business criticality, and locating the accountable owner for each instance before planning remediation.

  • Confirm Home Assistant instance ownership and exposure.
  • Verify if affected entity names are exposed.
  • Plan targeted updates or temporary risk reduction.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Home Assistant and what is it used for?

Home Assistant is a popular open-source software platform designed for smart home control. It serves as a central hub, allowing users to connect, automate, and manage various internet-connected devices, sensors, and lighting systems. It prioritizes local data privacy by running entirely on your own hardware rather than relying on external cloud services, making it a key component for personalized home management.

What does CVE-2026-91130 mean for software security?

This CVE describes a weakness classified as CWE-80, or Improper Neutralization of Script-Related HTML Tags. In plain terms, the software fails to properly sanitize text before displaying it. Because the Statistics Graph card does not scrub data inputs, an attacker can embed malicious code inside an entity name. When the browser renders this text as HTML, it treats the hidden code as a valid command, leading to unauthorized script execution.

How is this Home Assistant vulnerability triggered?

A trigger requires a specifically crafted entity name to be processed by the Statistics Graph card in a Line chart configuration. The malicious code activates only when an authenticated user hovers their mouse pointer over a data point on the graph. Notably, Bar charts are not impacted by this flaw, and the issue does not execute automatically; it depends entirely on the user interaction of viewing and hovering over the affected chart data.

Do I need to worry if my Home Assistant is internal?

While Halo Surface Signal identifies this as a network-based vulnerability, the actual risk depends on your specific setup. Because this requires an authenticated user or a compromised integration to provide the malicious input, instances isolated on internal networks are generally at lower risk than those exposed to the public internet. If you use Home Assistant for personal use within your own home network, your exposure is limited compared to shared or remote-access environments.

When should I update my Home Assistant software?

You should prioritize updating to version 2026.7.0 or newer immediately. As a first step, verify your current instance version and confirm you are using the Statistics Graph card. If you are running an older version, the update is the only way to ensure input sanitization is correctly enforced. Check your instance management dashboard to plan this update and minimize the window of potential risk within your home automation environment.

References