
CVE-2026-32112 ha-mcp is a Home Assistant MCP Server. Prior to 7.0.0, the ha-mcp OAuth consent form renders user-controlled parameters via Python f-strings with no HTML escaping. An… https://www.cve.org/CVERecord?id=CVE-2026-32112
Post summary
CVE-2026-32112 reveals that Home Assistant's MCP OAuth consent form unsafely renders user-controlled parameters, creating a potential XSS vulnerability, with no evidence of active exploitation or patching.
