CVE-2026-91130
Home Assistant: XSS in Statistics Graph Card
Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.7.0, the Statistics Graph card in src/components/chart/statistics-chart.ts passed entity names through getStatisticLabel and computeStateName and interpolated param.seriesName into ECharts tooltip HTML without escaping. An authenticated user or an integration that supplies a malicious default entity name could cause script-related HTML to execute when a viewer hovered over a data point. Mean, State, Sum, and Change fields in the default Line chart configuration were affected, while Bar charts were not. This issue is fixed in version 2026.7.0.
| CWE | CWE-80 |
| Vendor | home-assistant |
| Product | core |
| Published | Sep 22, 2026 |
| Last Updated | Sep 22, 2026 |
Get instant alerts for home-assistant core
Be the first to know when new unknown vulnerabilities affecting home-assistant core are published โ delivered to Slack, Telegram or Discord.