In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsLearn about Cross-site Request Forgery (CSRF) vulnerabilities in an interactive lesson.
Start learningUpgrade ha-mcp to version 7.7.0 or higher.
ha-mcp is a Home Assistant MCP Server - Complete control of Home Assistant through MCP
Affected versions of this package are vulnerable to Cross-site Request Forgery (CSRF) in the exposed api/settings routes when accessed at the bare root path without authentication. An attacker can modify configuration settings, toggle feature flags, manage backups, restart the add-on, or alter approval policies by sending crafted HTTP requests to the affected endpoints. This is only exploitable if the Home Assistant add-on is installed with host_network: true and port 9583 is published, allowing unauthenticated access to the root-mounted routes.