<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 16:07:26 +0000</lastBuildDate>
    <item>
      <title>CVE-2025-62172 — Home Assistant vulnerable to Stored XSS in Energy dashboard from Energy Entity Name</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2025-62172</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; home-assistant core&lt;/p&gt;
&lt;p&gt;Home Assistant is open source home automation software that puts local control and privacy first. In versions 2025.1.0 through 2025.10.1, the energy dashboard is vulnerable to stored cross-site scripting. An authenticated user can inject malicious JavaScript code into an energy entity&amp;#39;s name field, which is then executed when any user hovers over data points in the energy dashboard graph tooltips. The vulnerability exists because entity names containing HTML are not properly sanitized before being rendered in graph tooltips. This could allow an attacker with authentication to execute arbitrary JavaScript in the context of other users&amp;#39; sessions. Additionally, if an energy provider (such as Tibber) supplies a malicious default name for an entity, the vulnerability can be exploited without direct user action when the default name is used. This issue has been patched in version 2025.10.2. No known workarounds exist.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; home-assistant core&lt;/p&gt;
&lt;p&gt;Home Assistant is open source home automation software that puts local control and privacy first. In versions 2025.1.0 through 2025.10.1, the energy dashboard is vulnerable to stored cross-site scripting. An authenticated user can inject malicious JavaScript code into an energy entity&amp;#39;s name field, which is then executed when any user hovers over data points in the energy dashboard graph tooltips. The vulnerability exists because entity names containing HTML are not properly sanitized before being rendered in graph tooltips. This could allow an attacker with authentication to execute arbitrary JavaScript in the context of other users&amp;#39; sessions. Additionally, if an energy provider (such as Tibber) supplies a malicious default name for an entity, the vulnerability can be exploited without direct user action when the default name is used. This issue has been patched in version 2025.10.2. No known workarounds exist.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2025-62172</guid>
    </item>
    <item>
      <title>GHSA-mq77-rv97-285m — Home Assistant has Stored XSS vulnerability in Energy dashboard from Energy Entity Name</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-mq77-rv97-285m</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: homeassistant&lt;/p&gt;
&lt;p&gt;### Summary
An authenticated party can add a malicious name to the Energy entity, allowing for Cross-Site Scripting attacks against anyone who can see the Energy dashboard, when they hover over any information point (The blue bar in the picture below)
&amp;lt;img width=&amp;#34;955&amp;#34; height=&amp;#34;568&amp;#34; alt=&amp;#34;1_cens&amp;#34; src=&amp;#34;https://github.com/user-attachments/assets/ed855216-c306-4b50-affc-cda100e72b74&amp;#34; /&amp;gt;&lt;/p&gt;
&lt;p&gt;An alternative, and more impactful scenario, is that the entity gets a malicious name from the provider of the Entity (in this case the energy provider: Tibber), and gets exploited that way, through the default name.&lt;/p&gt;
&lt;p&gt;### Details
The incriminating entity in my scenario is from the Tibber integration, as shown in the screenshot below:
&amp;lt;img width=&amp;#34;822&amp;#34; height=&amp;#34;309&amp;#34; alt=&amp;#34;2_cens&amp;#34; src=&amp;#34;https://github.com/user-attachments/assets/d0d5a7aa-8d0c-4dcb-825b-e4cb8ea8885b&amp;#34; /&amp;gt;&lt;/p&gt;
&lt;p&gt;The exploit should be possible regardless of the Energy integration, as the user can name the entity themselves and as such pick a malicious name. The default name given by the Energy integration can also be taken directly from their system, and be vulnerable that way. The execution happens within the energy dashboard, when hovering over a data point:&lt;/p&gt;
&lt;p&gt;&amp;lt;img width=&amp;#34;1545&amp;#34; height=&amp;#34;571&amp;#34; alt=&amp;#34;image&amp;#34; src=&amp;#34;https://github.com/user-attachments/assets/46dc7f00-4593-4271-8c3f-4c02b021ff2b&amp;#34; /&amp;gt;&lt;/p&gt;
&lt;p&gt;**Update found after issue was reported:**
I found that the issue presents itself for any entity with a html-entity in the name, which is included and re…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: homeassistant&lt;/p&gt;
&lt;p&gt;### Summary
An authenticated party can add a malicious name to the Energy entity, allowing for Cross-Site Scripting attacks against anyone who can see the Energy dashboard, when they hover over any information point (The blue bar in the picture below)
&amp;lt;img width=&amp;#34;955&amp;#34; height=&amp;#34;568&amp;#34; alt=&amp;#34;1_cens&amp;#34; src=&amp;#34;https://github.com/user-attachments/assets/ed855216-c306-4b50-affc-cda100e72b74&amp;#34; /&amp;gt;&lt;/p&gt;
&lt;p&gt;An alternative, and more impactful scenario, is that the entity gets a malicious name from the provider of the Entity (in this case the energy provider: Tibber), and gets exploited that way, through the default name.&lt;/p&gt;
&lt;p&gt;### Details
The incriminating entity in my scenario is from the Tibber integration, as shown in the screenshot below:
&amp;lt;img width=&amp;#34;822&amp;#34; height=&amp;#34;309&amp;#34; alt=&amp;#34;2_cens&amp;#34; src=&amp;#34;https://github.com/user-attachments/assets/d0d5a7aa-8d0c-4dcb-825b-e4cb8ea8885b&amp;#34; /&amp;gt;&lt;/p&gt;
&lt;p&gt;The exploit should be possible regardless of the Energy integration, as the user can name the entity themselves and as such pick a malicious name. The default name given by the Energy integration can also be taken directly from their system, and be vulnerable that way. The execution happens within the energy dashboard, when hovering over a data point:&lt;/p&gt;
&lt;p&gt;&amp;lt;img width=&amp;#34;1545&amp;#34; height=&amp;#34;571&amp;#34; alt=&amp;#34;image&amp;#34; src=&amp;#34;https://github.com/user-attachments/assets/46dc7f00-4593-4271-8c3f-4c02b021ff2b&amp;#34; /&amp;gt;&lt;/p&gt;
&lt;p&gt;**Update found after issue was reported:**
I found that the issue presents itself for any entity with a html-entity in the name, which is included and re…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-mq77-rv97-285m</guid>
    </item>
  </channel>
</rss>
