PT-2026-61960 · Unknown · Home Assistant Core

·

CVE-2026-64823

·

Published

2026-07-21

·

Updated

2026-07-21

CVSS v3.1

4.7

Medium

VectorAV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Home Assistant Core versions prior to 2026.5.4
Description A cross-site scripting issue exists in the Shelly integration's async get media image() function. An attacker who controls a Shelly device's thumb field can serve arbitrary HTML content by providing a data URI with a text/html content type, as the system fails to validate the input against an image-only allowlist. This allows the media player proxy endpoint to serve attacker-controlled bytes with a text/html Content-Type within the Home Assistant web origin. Consequently, this can lead to the theft of session tokens from local storage and the execution of authenticated calls to sensitive service endpoints, such as those controlling locks, alarms, and covers.
Recommendations Update Home Assistant Core to version 2026.5.4 or later.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-64823

Affected Products

Home Assistant Core