esphome vulnerabilities

ESPHome is a system to configure your microcontrollers by simple yet powerful configuration files and control them remotely through Home Automation systems.

  • latest version

    2025.9.3

  • latest non vulnerable version

  • first published

    6 years ago

  • latest version published

    7 days ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the esphome package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • H
    Incorrect Implementation of Authentication Algorithm

    [,2025.8.1)
    • H
    Cross-Site Request Forgery (CSRF)

    [2023.12.9,2024.3.0)
    • M
    Cross-site Scripting (XSS)

    [2023.12.9,2024.2.2)
    • H
    Path Traversal

    [,2024.2.1)
    • H
    Improper Authentication

    [,2021.9.2)

    Package versions

    506 VERSIONS IN TOTAL See all versions
    versionpublisheddirect vulnerabilities
    2025.9.31 Oct, 2025
    • 0
      C
    • 0
      H
    • 0
      M
    • 0
      L
    2025.9.229 Sep, 2025
    • 0
      C
    • 0
      H
    • 0
      M
    • 0
      L
    2025.9.119 Sep, 2025
    • 0
      C
    • 0
      H
    • 0
      M
    • 0
      L
    2025.9.017 Sep, 2025
    • 0
      C
    • 0
      H
    • 0
      M
    • 0
      L
    2025.9.0b416 Sep, 2025
    • 0
      C
    • 0
      H
    • 0
      M
    • 0
      L
    2025.9.0b316 Sep, 2025
    • 0
      C
    • 0
      H
    • 0
      M
    • 0
      L
    2025.9.0b215 Sep, 2025
    • 0
      C
    • 0
      H
    • 0
      M
    • 0
      L
    2025.9.0b110 Sep, 2025
    • 0
      C
    • 0
      H
    • 0
      M
    • 0
      L
    2025.8.410 Sep, 2025
    • 0
      C
    • 0
      H
    • 0
      M
    • 0
      L
    2025.8.34 Sep, 2025
    • 0
      C
    • 0
      H
    • 0
      M
    • 0
      L