Home Assistant是Home Assistant组织开源的一套开源的家庭自动化管理系统。该系统主要用于控制家庭自动化设备。 Home Assistant 2026.5.4之前版本存在跨站脚本漏洞,该漏洞源于Shelly集成的async_get_media_image()方法容易受到跨站脚本攻击,原因在于用户提供的data URI包含text/html内容类型且未通过仅图像白名单验证,从而导致攻击者通过控制Shelly设备的thumb字段提供任意HTML内容,可能导致会话令牌被盗和锁定、警报及覆盖
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| home-assistant | Home Assistant Core | < 2026.5.4 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| home-assistant | Home Assistant Core | 0 ~ 2026.5.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-64825 | 9.3 CRITICAL | Home Assistant Core < 2026.6.0 Path Traversal File Write via Backup Upload |
| CVE-2026-64824 | 8.4 HIGH | Home Assistant Core < 2026.7.0 Symlink Path Traversal RCE via backup-restore |
No comments yet