esphome vulnerabilities

ESPHome is a system to configure your microcontrollers by simple yet powerful configuration files and control them remotely through Home Automation systems.

  • latest version

    2025.8.4

  • latest non vulnerable version

  • first published

    6 years ago

  • latest version published

    5 days ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the esphome package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • H
    Incorrect Implementation of Authentication Algorithm

    [,2025.8.1)
    • H
    Cross-Site Request Forgery (CSRF)

    [2023.12.9,2024.3.0)
    • M
    Cross-site Scripting (XSS)

    [2023.12.9,2024.2.2)
    • H
    Path Traversal

    [,2024.2.1)
    • H
    Improper Authentication

    [,2021.9.2)

    Package versions

    500 VERSIONS IN TOTAL See all versions
    versionpublisheddirect vulnerabilities
    2025.9.0b215 Sep, 2025
    • 0
      C
    • 0
      H
    • 0
      M
    • 0
      L
    2025.9.0b110 Sep, 2025
    • 0
      C
    • 0
      H
    • 0
      M
    • 0
      L
    2025.8.410 Sep, 2025
    • 0
      C
    • 0
      H
    • 0
      M
    • 0
      L
    2025.8.34 Sep, 2025
    • 0
      C
    • 0
      H
    • 0
      M
    • 0
      L
    2025.8.229 Aug, 2025
    • 0
      C
    • 0
      H
    • 0
      M
    • 0
      L
    2025.8.125 Aug, 2025
    • 0
      C
    • 0
      H
    • 0
      M
    • 0
      L
    2025.8.020 Aug, 2025
    • 0
      C
    • 1
      H
    • 0
      M
    • 0
      L
    2025.8.0b419 Aug, 2025
    • 0
      C
    • 1
      H
    • 0
      M
    • 0
      L
    2025.8.0b319 Aug, 2025
    • 0
      C
    • 1
      H
    • 0
      M
    • 0
      L
    2025.8.0b214 Aug, 2025
    • 0
      C
    • 1
      H
    • 0
      M
    • 0
      L