Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
ESPHome external_components file:// Scheme Validation Bypass Leading to Remote Code Execution
Vulnerability Description
ESPHome through 2026.7.0-dev contains an operator-precedence bug in the cv.url validator in esphome/config_validation.py. Because binds tighter than , any file: URI passes validation regardless of netloc. This validator gates the field of the external_components YAML directive's git source schema, which is passed to (git supports file:// natively).
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Vulnerability Type
不完整的黑名单
Vulnerability Title
ESPHome 输入验证错误漏洞
Vulnerability Description
ESPHome是ESPHome组织开源的一款智能家居设备控制平台。 ESPHome 2026.7.0-dev及之前版本存在输入验证错误漏洞,该漏洞源于cv.url()验证器中存在运算符优先级错误,导致攻击者可通过特制的external_components配置块绕过验证并执行任意Python代码。
CVSS Information
N/A
Vulnerability Type
N/A