VYPR

Home Assistant Mcp Server

by Homeassistant AI

Source repositories

CVEs (3)

  • CVE-2026-66060HigAug 7, 2026
    risk 0.39cvss 7.1epss 0.00

    Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.5.3, the Companion app treats tag links (NFC or QR) delivered through an OS-level routing mechanism as if they were physically scanned, without validating the calling app…

  • CVE-2026-32112MedMar 11, 2026
    risk 0.37cvss 6.8epss 0.00

    ha-mcp is a Home Assistant MCP Server. Prior to 7.0.0, the ha-mcp OAuth consent form renders user-controlled parameters via Python f-strings with no HTML escaping. An attacker who can reach the OAuth endpoint and convince the server operator to follow a crafted authorization URL…

  • CVE-2026-32111MedMar 11, 2026
    risk 0.27cvss 5.3epss 0.00

    ha-mcp is a Home Assistant MCP Server. Prior to 7.0.0, the ha-mcp OAuth consent form (beta feature) accepts a user-supplied ha_url and makes a server-side HTTP request to {ha_url}/api/config with no URL validation. An unauthenticated attacker can submit arbitrary URLs to perform…