Skip to main content
Loading…
    CVE-2026-32112 — ha-mcp is a Home Assistant MCP Server. Prior to 7.0.0, the ha-mcp OAuth consent form renders user-controlled parameters via Python f-strings with no HTML escaping. An attacker who can reach the OAuth — CVE Database · The Intelligence Room