CVE-2026-32112 | homeassistant-ai ha-mcp up to 6.x OAuth Endpoint cross site scripting (GHSA-pf93-j98v-25pv)
A vulnerability marked as problematic has been reported in homeassistant-ai ha-mcp up to 6.x. This issue affects some unknown processing of the component OAuth Endpoint. The manipulation leads to cross site scripting.
This vulnerability is referenced as CVE-2026-32112. Remote exploitation of the attack is possible. No exploit is available.
It is suggested to upgrade the affected component.