Executive brief
The Home Assistant MCP Server integration, which allows AI models to interact with Home Assistant, contains a vulnerability where configuration backups are stored in a publicly accessible folder. If the YAML editing feature is enabled, any user on the same network can download these backups without a password. These files often contain sensitive information such as plaintext passwords for smart home services, security credentials, and private location coordinates.
Technical details
The vulnerability is classified as CWE-552 (Files or Directories Accessible to External Parties). When 'ENABLE_YAML_CONFIG_EDITING' is set to true, the 'ha_config_set_yaml' function saves backups to the 'www/yaml_backups/' directory. By design, Home Assistant serves the 'www/' directory at the '/local/' endpoint without authentication to facilitate static dashboard assets. An attacker on the local network (or internet if the instance is exposed) can guess or discover the backup filenames—which use a predictable timestamp format—and download them without credentials. These backups typically contain sensitive data like MQTT passwords and REST credentials. The issue is fixed in version 7.5.0 by moving backups to a non-public directory and migrating existing files.
Affected products
- homeassistant-ai ha-mcp < 7.5.0
Timeline
- 2026-05-08: disclosed: Vulnerability reported and published to repository advisory database.
- 2026-05-14: advisory: GitHub Advisory GHSA-g39v-cvjh-8fpf published.
- 2026-05-14: patched: Fixed in version 7.5.0.