home-assistant-frontend@20251126.0

The Home Assistant frontend

  • latest version

    20260729.7

  • latest non vulnerable version

  • first published

    8 years ago

  • latest version published

    10 days ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the home-assistant-frontend package. This does not include vulnerabilities belonging to this package’s dependencies.

    Fix vulnerabilities automatically

    Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

    Fix for free
    VulnerabilityVulnerable Version
    • L
    Cross-site Scripting (XSS)

    home-assistant-frontend is a The Home Assistant frontend

    Affected versions of this package are vulnerable to Cross-site Scripting (XSS) in the rendering of device entity names within the map-card component when the hours_to_show attribute is set. An attacker can execute arbitrary JavaScript in the context of another user's session by crafting a malicious device name and having a victim hover over a data point on the map-card displaying that entity.

    Note: This is only exploitable if the map-card is configured to display an entity with a malicious name and the hours_to_show attribute is enabled.

    How to fix Cross-site Scripting (XSS)?

    Upgrade home-assistant-frontend to version 20260107.2 or higher.

    [20240202.0,20260107.2)
    • L
    Cross-site Scripting (XSS)

    home-assistant-frontend is a The Home Assistant frontend

    Affected versions of this package are vulnerable to Cross-site Scripting (XSS) via the History-graph card in the history graph display component. An attacker can execute arbitrary JavaScript in a victim’s browser by supplying a malicious entity name that is rendered in the graph. When the card shows a line graph with values on the x and y axis, it may display the entity name without output escaping or sanitization. This can affect sensors or devices whose names are shown in the graph, including the remaining charge time sensor imported from Android Auto.

    How to fix Cross-site Scripting (XSS)?

    Upgrade home-assistant-frontend to version 20260107.2 or higher.

    [20240202.0,20260107.2)