Executive brief
Home Assistant Command-line Interface is a tool used to interact with Home Assistant instances through templates. Prior to version 1.0.0, the CLI failed to sandbox user-supplied Jinja2 templates, allowing an attacker to execute arbitrary Python code on a user's local machine by tricking them into rendering a malicious template file. This could enable data theft, system compromise, or establishing unauthorized remote access.
Technical details
The vulnerability is a template injection / code injection flaw (CWE-94, CWE-1336) in home-assistant-cli's handling of Jinja2 templates. Prior to version 1.0.0, templates were rendered in an unrestricted Jinja2 environment, allowing direct access to Python's internals via expressions like `environ.__globals__['__builtins__']`. An attacker can craft a malicious .j2 template file and social engineer a user into downloading and rendering it locally using the `hass-cli template --local` command. Successful exploitation requires user interaction and administrator privileges on the local system, but results in arbitrary code execution with the user's privileges. The fix in version 1.0.0 uses ImmutableSandboxedEnvironment and restricts environment variable access.
Affected products
- Home Assistant homeassistant-cli before 1.0.0
Timeline
- 2026-04-16: disclosed
- 2026-04-16: patched: Fixed in version 1.0.0
- 2026-04-21: other: CVE-2026-40602 published on NVD