PT-2026-61960 · Unknown · Home Assistant Core
CVSS v3.1
4.7
Medium
| Vector | AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Home Assistant Core versions prior to 2026.5.4
Description
A cross-site scripting issue exists in the Shelly integration's
async get media image() function. An attacker who controls a Shelly device's thumb field can serve arbitrary HTML content by providing a data URI with a text/html content type, as the system fails to validate the input against an image-only allowlist. This allows the media player proxy endpoint to serve attacker-controlled bytes with a text/html Content-Type within the Home Assistant web origin. Consequently, this can lead to the theft of session tokens from local storage and the execution of authenticated calls to sensitive service endpoints, such as those controlling locks, alarms, and covers.Recommendations
Update Home Assistant Core to version 2026.5.4 or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Home Assistant Core