What is CVE-2026-59717?
This CVE identifies an open redirect vulnerability in the Home Assistant Android Companion app. The app passes the URL fragment from a "homeassistant://invite" deep link into the onboarding flow without displaying it, which could lead to phishing attacks. Versions prior to 2026.6.1 are affected, and users are advised to update immediately.
Azərbaycanca: Bu CVE, Home Assistant Android Companion tətbiqində aşkarlanmış açıq yönləndirmə (open redirect) zəifliyidir. Tətbiq, "homeassistant://invite" deep linkindən gələn URL fragmentini istifadəçiyə göstərmədən onboarding axınına ötürür, bu da potensial fişinq hücumlarına yol aça bilər. 2026.6.1 versiyasından əvvəlki versiyalar təsirlənir, istifadəçilərə dərhal yeniləmə tövsiyə olunur.
FAQ2
How can I protect against CVE-2026-59717 in the Home Assistant Android Companion app?
Update the app to version 2026.6.1 or later.
What type of attack does CVE-2026-59717 refer to?
It is an open redirect vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.