MEDIUM5.3PyPI
PYSEC-2026-2507· CVE-2026-32111, GHSA-fmfg-9g7c-3vq7ha-mcp OAuth 2.1 DCR mode enables network reconnaissance via an error oracle
Modified: 7/13/2026
package
pkg:pypi/ha-mcp
ha-mcp OAuth 2.1 DCR mode enables network reconnaissance via an error oracle
Modified: 7/13/2026
ha-mcp has XSS via Unescaped HTML in OAuth Consent Form
Modified: 7/13/2026
ha-mcp OAuth 2.1 DCR mode enables network reconnaissance via an error oracle
Modified: 7/13/2026
Home Assistant MCP Server: YAML config backups written under www/ are served unauthenticated at /local/
Modified: 5/14/2026
ha-mcp has XSS via Unescaped HTML in OAuth Consent Form
Modified: 7/13/2026
ha-mcp: Add-on settings and policy routes are reachable without authentication at the bare root path
Modified: 7/7/2026