depscope
Packages
IntegrateAPI DocsCuratorBenchmarkCoverage
Sign inGet API access
depscope/conda/homeassistant

homeassistant

condav2022.6.3

Open source home automation that puts local control and privacy first.

License Apache-2.0permissive61 versions1 maintainers0 deps894 weekly dl
home-assistant/core
37
/ 100
Health
update required

[email protected] has vulnerabilities — update to latest

Update to >= 2023.9.0 to fix known vulnerabilities

  • Low health score (37/100)
  • 1 high severity vulnerabilities
Health breakdown0 – 100
5/25
maintenance
3/20
popularity
12/25
security
15/15
maturity
2/15
community
Vulnerabilities
6
1 high4 medium1 low
Advisories (6)
SeverityIDSummaryFixed in
mediumCVE-2023-50715User accounts disclosed to unauthenticated actors on the LAN2023.12.3
highCVE-2025-25305Home Assistant does not correctly validate SSL for outgoing requests in core and used libs2024.1.6
mediumCVE-2025-65713Home Assistant Core before is vulnerable to Directory Traversal2025.8.0
mediumCVE-2023-41893Home Assistant vulnerable to account takeover via auth_callback login2023.9.0
lowCVE-2026-33044Home Assistant has stored XSS in Map-card through malicious device name2026.01
mediumCVE-2023-41893Home assistant is an open source home automation. The audit team’s analyses confirmed that the `redirect_uri` and `client_id` are alterable when logging in. Consequently, the code parameter utilized to fetch the `access_token` post-authentication will be sent to the URL specified in the aforementioned parameters. Since an arbitrary URL is permitted and `homeassistant.local` represents the preferred, default domain likely used and trusted by many users, an attacker could leverage this weakness to2023.9.0

Health History

Dependency Tree

License Audit

API access

Get this data programmatically — free, no authentication.

curl https://depscope.dev/api/check/conda/homeassistant

First published · 2021-10-01 00:53:27.549000+00:00

Last updated · 2025-04-22 14:58:01.617000+00:00

DepScope

Package intelligence for AI agents. 19 ecosystems.

Resources
API DocumentationHallucination BenchmarkFor EnterpriseSwagger / OpenAPIPopular PackagesCoverageAI Plugin SetupWatch the pitch (60s)
Legal
Legal hubPrivacy PolicyTerms of ServiceCookie PolicyAcceptable UseAttributionDPASub-processorsSecurityImprintContact中文
© 2026 Cuttalo srl — Italy · VAT IT03242390734Built for AI agents