CVE-2026-91130
📛 CVE Title
Home Assistant: XSS in Statistics Graph Card
Description
Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.7.0, the Statistics Graph card in src/components/chart/statistics-chart.ts passed entity names through getStatisticLabel and computeStateName and interpolated param.seriesName into ECharts tooltip HTML without escaping. An authenticated user or an integration that supplies a malicious default entity name could cause script-related HTML to execute when a viewer hovered over a data point. Mean, State, Sum, and Change fields in the default Line chart configuration were affected, while Bar charts were not. This issue is fixed in version 2026.7.0.
Overview
- State
- PUBLISHED
- Assigner (CNA)
- GitHub_M
- CVSS severity
- CRITICAL
- CVSS score
- 9.3 / 10
- CVSS vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H- Effective score
- 9.3 / 10 CRITICAL source: CNA overview
- CWE(s)
-
CWE-80 - Reserved
- 2026-09-14
- Published
- 2026-09-22 19:02 UTC
- Last updated
- 2026-09-22 19:41 UTC
- Source
- https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/91xxx/CVE-2026-91130.json
- Linked Threat
- CVE-2026-91130 — Home Assistant: XSS in Statistics Graph Card
NVD triage scoring NVD CVE 2.0
Layer NVD adds on top of the CNA's CVE record — published / last-modified timestamps, exploitability / impact subscores, and the FIRST.org EPSS probability that this CVE will be exploited in the wild in the next 30 days.
- NVD published
- 2026-09-22 19:16:56 UTC
- NVD last modified
- 2026-09-22 20:17:11 UTC
NVD / KEV / EPSS data refreshed 2026-09-23 02:33 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.
European Union Vulnerability Database ENISA EUVD
ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.
- EUVD ID
-
EUVD-2026-84803 - Assigner
- GitHub_M
- Published
- Sep 22, 2026, 7:02:38 PM
- Updated
- Sep 22, 2026, 7:41:01 PM
- EUVD base score (CVSS 4.0)
-
9.3 / 10
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H - EUVD-reported EPSS
- 0.0000
- Vendors
- home-assistant
- Products
-
core (< 2026.7.0)
- Aliases
-
GHSA-wx4m-69m9-gx3m
ENISA description: Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.7.0, the Statistics Graph card in src/components/chart/statistics-chart.ts passed entity names through getStatisticLabel and computeStateName and interpolated param.seriesName into ECharts tooltip HTML without escaping. An authenticated user or an integration that supplies a malicious default entity name could cause script-related HTML to execute when a viewer hovered over a data point. Mean, State, Sum, and Change fields in the default Line chart configuration were affected, while Bar charts were not. This issue is fixed in version 2026.7.0.
EUVD references (4)
Affected products (1)
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| home-assistant | core |
< 2026.7.0 (affected)
|
— |
Vendor references (4)
References embedded in the original CVE record by the assigning CNA.
- https://github.com/home-assistant/core/security/advisories/GHSA-wx4m-69m9-gx3m x_refsource_CONFIRM
- https://github.com/home-assistant/frontend/pull/52235 x_refsource_MISC
- https://github.com/home-assistant/frontend/commit/b8c201b6d34414d30c622797366570185c219614 x_refsource_MISC
- https://github.com/home-assistant/core/releases/tag/2026.7.0 x_refsource_MISC
Web references (0)
DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.
No web references attached yet.
NVD-tagged references (5)
Reference list NVD curates from the CNA record, vendor advisories, and third-party reports. The tag chips below are NVD's analyst-assigned categories.
- https://github.com/home-assistant/core/releases/tag/2026.7.0 security-advisories@github.com
- https://github.com/home-assistant/core/security/advisories/GHSA-wx4m-69m9-gx3m security-advisories@github.com
- https://github.com/home-assistant/core/security/advisories/GHSA-wx4m-69m9-gx3m 134c704f-9b21-4f2e-91b3-4a467353bcc0
- https://github.com/home-assistant/frontend/commit/b8c201b6d34414d30c622797366570185c219614 security-advisories@github.com
- https://github.com/home-assistant/frontend/pull/52235 security-advisories@github.com
Remediations (10)
Remediations are stored against the linked Threat row; the list below is deduplicated across both pages.
-
web:cvetodo.com
CVE-2026-91130 is a CVSS 9.3 critical-severity vulnerability in Home-assistant Core. See exploitation status, patch guidance, and technical details.
2026-09-23 15:14 UTC -
web:my.f5.com
On September 2, 2026 , F5 announced the following security issues. This document is intended to serve as an index of these vulnerabilities and security exposures to help determine the impact to your F5 devices. You can find the details of each issue in the associated articles.
2026-09-23 15:14 UTC -
web:sec.cloudapps.cisco.com
On September 16, 2026 , the Cisco Product Security Incident Response Team (PSIRT) published the advisories that are listed in the following tables. To remediate these vulnerabilities, Cisco strongly recommends that customers upgrade to the fixed software that is indicated in the advisories. For more information about changes in Cisco PSIRT vulnerability disclosure, see Strengthening the ...
2026-09-23 15:14 UTC -
web:securityarsenal.com
Cisco ISE and ISE-PIC admins face 12 critical network-exploitable CVEs rated up to CVSS 10. Patch , lock down admin interfaces, and hunt for post-exploitation now.
2026-09-23 15:14 UTC -
web:senserva.com
Every Microsoft security patch (KB) and the CVEs it fixes, with severity, CVSS, and CISA KEV status. Cross-linked to the CVE reference.
2026-09-23 15:14 UTC -
web:www.fortra.com
Analyze Oracle's September 2026 Critical Security Patch Update, including 673 patches, 246 remotely exploitable CVEs , and key vulnerabilities with CVSS scores up to 10.0.
2026-09-23 15:14 UTC -
web:www.ibm.com
Remediation /Fixes IBM strongly recommends addressing the vulnerability now by applying a currently available interim fix or fix pack that contains the fix for APAR PH71453. For IBM WebSphere Application Server traditional: For V9.0.0.0 through 9.0.5.28: · Upgrade to minimal fix pack levels as required by the interim fix and then apply the Interim Fix that resolves PH71453 -- OR -- · Apply Fix ...
2026-09-23 15:14 UTC -
web:www.ibm.com
Remediation /Fixes IBM strongly recommends addressing the vulnerability now by applying a currently available interim fix or fix pack that contains the fix for APAR PH71453, as described in Security Bulletin: IBM WebSphere Application Server is affected by remote code execution ( CVE - 2026 -9311, CVE - 2026 -9330)
2026-09-23 15:14 UTC -
web:www.oracle.com
This Critical Patch Update contains 1448 new security patches across the product families listed below. Please note that a My Oracle Support (MOS) note summarizing the content of this Critical Patch Update and other Oracle Software Security Assurance activities is located at July 2026 Critical Patch Update: Executive Summary and Analysis.
2026-09-23 15:14 UTC -
web:www.secpod.com
Patch Timeline & Exploitation Gap Analysis The September 16, 2026 dataset contains three CISA KEV vulnerabilities. Each record was added to the catalog on September 16, 2026 and assigned a remediation deadline of September 19, 2026 . Consequently, all three vulnerabilities have an identical three-calendar-day KEV inclusion-to- remediation window.
2026-09-23 15:14 UTC
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.
Raw JSON
The full cvelistV5 record. Download as CVE-2026-91130.json.
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-91130",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-22T19:39:45.840965Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-22T19:41:01.261Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"tags": [
"exploit"
],
"url": "https://github.com/home-assistant/core/security/advisories/GHSA-wx4m-69m9-gx3m"
}
],
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "core",
"vendor": "home-assistant",
"versions": [
{
"status": "affected",
"version": "< 2026.7.0"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.7.0, the Statistics Graph card in src/components/chart/statistics-chart.ts passed entity names through getStatisticLabel and computeStateName and interpolated param.seriesName into ECharts tooltip HTML without escaping. An authenticated user or an integration that supplies a malicious default entity name could cause script-related HTML to execute when a viewer hovered over a data point. Mean, State, Sum, and Change fields in the default Line chart configuration were affected, while Bar charts were not. This issue is fixed in version 2026.7.0."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 9.3,
"baseSeverity": "CRITICAL",
"privilegesRequired": "LOW",
"subAvailabilityImpact": "HIGH",
"subConfidentialityImpact": "HIGH",
"subIntegrityImpact": "HIGH",
"userInteraction": "ACTIVE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-80",
"description": "CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-22T19:02:38.916Z",
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M"
},
"references": [
{
"name": "https://github.com/home-assistant/core/security/advisories/GHSA-wx4m-69m9-gx3m",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/home-assistant/core/security/advisories/GHSA-wx4m-69m9-gx3m"
},
{
"name": "https://github.com/home-assistant/frontend/pull/52235",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/home-assistant/frontend/pull/52235"
},
{
"name": "https://github.com/home-assistant/frontend/commit/b8c201b6d34414d30c622797366570185c219614",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/home-assistant/frontend/commit/b8c201b6d34414d30c622797366570185c219614"
},
{
"name": "https://github.com/home-assistant/core/releases/tag/2026.7.0",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/home-assistant/core/releases/tag/2026.7.0"
}
],
"source": {
"advisory": "GHSA-wx4m-69m9-gx3m",
"discovery": "UNKNOWN"
},
"title": "Home Assistant: XSS in Statistics Graph Card"
}
},
"cveMetadata": {
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"assignerShortName": "GitHub_M",
"cveId": "CVE-2026-91130",
"datePublished": "2026-09-22T19:02:38.916Z",
"dateReserved": "2026-09-14T19:36:48.844Z",
"dateUpdated": "2026-09-22T19:41:01.261Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}