CVEs (2)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Homeassistant Ai 1Home Assistant Mcp Server Mar 17, 2026 Mar 11, 2026 N/A· v4 4.7 MEDIUM· v3 N/A· v2 ha-mcp is a Home Assistant MCP Server. Prior to 7.0.0, the ha-mcp OAuth consent form renders user-controlled parameters via Python f-strings with no HTML escaping. An attacker who can reach the OAuth endpoint and convinc...Show more |
1Homeassistant Ai 1Home Assistant Mcp Server Mar 17, 2026 Mar 11, 2026 N/A· v4 5.3 MEDIUM· v3 N/A· v2 ha-mcp is a Home Assistant MCP Server. Prior to 7.0.0, the ha-mcp OAuth consent form (beta feature) accepts a user-supplied ha_url and makes a server-side HTTP request to {ha_url}/api/config with no URL validation. An un...Show more |