CVE-2026-64823: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in home-assistant Home Assistant Core
Home Assistant Core before 2026.5.4 contains a cross-site scripting vulnerability in the Shelly integration's async_get_media_image() method that allows attackers controlling a Shelly device's thumb field to serve arbitrary HTML content by supplying a data URI with a text/html content type without validation against an image-only allowlist. Attackers can cause the media player proxy endpoint to serve attacker-controlled bytes with Content-Type text/html in the Home Assistant web origin, enabling theft of session tokens from local storage and authenticated calls to sensitive service endpoints including lock, alarm, and cover controls.
AI Analysis
Technical Summary
CVE-2026-64823 is a cross-site scripting vulnerability in Home Assistant Core prior to version 2026.5.4, specifically in the Shelly integration's async_get_media_image() method. The vulnerability arises because the method does not properly validate the content type of data URIs supplied via the Shelly device's thumb field, allowing an attacker to serve arbitrary HTML content with a text/html content type instead of restricting to image types. This leads to the media player proxy endpoint serving attacker-controlled bytes in the Home Assistant web origin, enabling session token theft from local storage and unauthorized authenticated actions on sensitive service endpoints such as locks, alarms, and covers.
Potential Impact
An attacker controlling a Shelly device's thumb field can exploit this vulnerability to inject arbitrary HTML content into the Home Assistant web interface. This can lead to theft of session tokens stored locally and allow the attacker to perform authenticated calls to sensitive service endpoints, potentially compromising device controls like locks, alarms, and covers. The CVSS 4.0 score is low (2.1) with network attack vector, high attack complexity, no privileges required, and user interaction needed. No known exploits in the wild have been reported.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. The vulnerability affects versions prior to 2026.5.4. Users should upgrade to version 2026.5.4 or later once available. Until a patch is applied, restrict access to Shelly devices and the Home Assistant interface to trusted users only to reduce risk.
CVE-2026-64823: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in home-assistant Home Assistant Core
Description
Home Assistant Core before 2026.5.4 contains a cross-site scripting vulnerability in the Shelly integration's async_get_media_image() method that allows attackers controlling a Shelly device's thumb field to serve arbitrary HTML content by supplying a data URI with a text/html content type without validation against an image-only allowlist. Attackers can cause the media player proxy endpoint to serve attacker-controlled bytes with Content-Type text/html in the Home Assistant web origin, enabling theft of session tokens from local storage and authenticated calls to sensitive service endpoints including lock, alarm, and cover controls.
CVSS v4.0
Score 2.1low
Affected software
pkg:github/Home Assistant CoreRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-64823 is a cross-site scripting vulnerability in Home Assistant Core prior to version 2026.5.4, specifically in the Shelly integration's async_get_media_image() method. The vulnerability arises because the method does not properly validate the content type of data URIs supplied via the Shelly device's thumb field, allowing an attacker to serve arbitrary HTML content with a text/html content type instead of restricting to image types. This leads to the media player proxy endpoint serving attacker-controlled bytes in the Home Assistant web origin, enabling session token theft from local storage and unauthorized authenticated actions on sensitive service endpoints such as locks, alarms, and covers.
Potential Impact
An attacker controlling a Shelly device's thumb field can exploit this vulnerability to inject arbitrary HTML content into the Home Assistant web interface. This can lead to theft of session tokens stored locally and allow the attacker to perform authenticated calls to sensitive service endpoints, potentially compromising device controls like locks, alarms, and covers. The CVSS 4.0 score is low (2.1) with network attack vector, high attack complexity, no privileges required, and user interaction needed. No known exploits in the wild have been reported.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. The vulnerability affects versions prior to 2026.5.4. Users should upgrade to version 2026.5.4 or later once available. Until a patch is applied, restrict access to Shelly devices and the Home Assistant interface to trusted users only to reduce risk.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-07-20T18:27:48.160Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a5f900b2a4a8d598955b737
Added to database: 07/21/2026, 15:28:11 UTC
Last enriched: 07/21/2026, 15:42:17 UTC
Last updated: 07/21/2026, 17:33:29 UTC
Views: 8
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.