Vulnerability Description
Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.6.1, the Android Companion app is vulnerable to an open redirect. The app passes the URL fragment from a homeassistant://invite deep link into the onboarding flow without ever displaying the destination hostname. Because no screen in the invitation or onboarding flow shows the parsed server URL before onboarding commits to it, a victim has no way to distinguish a legitimate invite from a malicious one. An attacker can craft an invite so that a single tap on the legitimate-looking "Connect to my Home Assistant server" button opens their /auth/authorize endpoint in the URL-less onboarding WebView, presenting a look-alike login page that captures the victim's credentials. Since invitations are intended to onboard brand-new users, targets are especially unlikely to notice the substitution. This issue is fixed in version 2026.6.1.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://github.com/home-assistant/android/commit/26154d923c3813cd4650e124900780f
- https://github.com/home-assistant/android/pull/6955
- https://github.com/home-assistant/core/security/advisories/GHSA-68f4-97mf-f68w
- https://github.com/home-assistant/core/security/advisories/GHSA-68f4-97mf-f68w
FAQ
What is CVE-2026-59717?
CVE-2026-59717 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.6.1, the Android Companion app is vulnerable to an open redirect. The app passes the URL frag...
How severe is CVE-2026-59717?
CVE-2026-59717 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-59717?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.