CVE-2026-32111 | homeassistant-ai ha-mcp up to 6.x /api/config server-side request forgery (GHSA-fmfg-9g7c-3vq7)
A vulnerability was found in homeassistant-ai ha-mcp up to 6.x. It has been rated as critical. Affected by this vulnerability is an unknown functionality of the file /api/config. This manipulation causes server-side request forgery.
This vulnerability is handled as CVE-2026-32111. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is advised.