CVE-2026-91130 | home-assistant core up to 2026.6.0 Statistics Graph card statistics-chart.ts getStatisticLabel/computeStateName param.seriesName cross site scripting

SecurityVulns

A vulnerability, which was classified as problematic, has been found in home-assistant core 2025.5.0/2026.01/2026.5.3/2026.5.4/2026.6.0. This vulnerability affects the function getStatisticLabel/computeStateName of the file src/components/chart/statistics-chart.ts of the component Statistics Graph card. Performing a manipulation of the argument param.seriesName results in cross site scripting.

This vulnerability is known as CVE-2026-91130. Remote exploitation of the attack is possible. No exploit is available.

It is advisable to upgrade the affected component.VulDB Recent EntriesRead More