Horizon Alert
Summary of the vulnerability and why it matters
This vulnerability affects Home Assistant, an open-source home automation software, allowing an authenticated user to execute script-related HTML through a specific chart card when a viewer hovers over a data point. The primary concern is confirming if this specific functionality is used and if any malicious default entity names are present.
- Malicious HTML can run via a Home Assistant chart.
- It matters if users interact with specific chart data.
- Confirm usage and exposure of the affected feature.
Attack Path
How an attacker could exploit the issue
An attacker with existing authenticated access to Home Assistant could craft a malicious default entity name. When another user views a statistics graph containing this entity, hovering over a data point would trigger script execution within their browser. This could allow an attacker to compromise the session of the user viewing the graph.
- Requires authenticated user access.
- Triggered by viewing a crafted statistics graph.
- Leads to script execution in the browser.
Live Threat
Current exploitation, exposure, and threat context
This vulnerability could allow an authenticated user or integration to execute arbitrary HTML and script code within the Home Assistant frontend. When a user hovers over a data point in a statistics graph, malicious script embedded in an entity name could execute. This is possible when the Statistics Graph card is used with default Line chart configurations for Mean, State, Sum, or Change fields.
- System data and user interface are at risk.
- Malicious script executes on hover.
- Could lead to unauthorized actions or data leakage.
Operational Fix
Recommended remediation, mitigation, and detection steps
The Home Assistant platform team, alongside application owners, should coordinate efforts to address this vulnerability. The first practical step involves identifying all Home Assistant instances, confirming their exposure and business criticality, and locating the accountable owner for each instance before planning remediation.
- Confirm Home Assistant instance ownership and exposure.
- Verify if affected entity names are exposed.
- Plan targeted updates or temporary risk reduction.