CVE Feed

    Dashboard / CVE / CVE-2026-40602

    CVE-2026-40602

    The Home Assistant Command-line interface (hass-cli) is a command-line tool for Home Assistant. Up to 1.0.0 of home-assitant-cli an unrestricted environment was used to handle Jninja2 templates instead of a sandboxed one. The user-supplied input within Jinja2 templates was rendered locally with no restrictions. This gave users access to Python's internals and extended the scope of templating beyond the intended usage. This vulnerability is fixed in 1.0.0.

    Published:Apr 21, 2026
    Last Modified:Apr 27, 2026
    EPS:Apr 21, 2026
    EPSS Score:0.00019
    CVSS Score:5.6

    Affected Products

    Vendor
    Home-assistant
    Product
    Home-assistant
    Vendor
    Home-assistant-ecosystem
    Product
    Home Assistant Command-line Interface

    Exploits

    No exploit reference

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High