Cross-Site Scripting in Home Assistant Core's Shelly Integration
CVE-2026-64823
2.1LOW
What is CVE-2026-64823?
A cross-site scripting vulnerability exists in the Shelly integration of Home Assistant Core prior to version 2026.5.4. This vulnerability allows attackers, who gain control of the thumb field from a Shelly device, to serve arbitrary HTML content by providing a data URI with text/html content type. The lack of validation against an image-only allowlist enables the media player proxy endpoint to respond with attacker-controlled content, which can lead to the theft of session tokens from local storage. Furthermore, this vulnerability can allow unauthorized interactions with sensitive service endpoints, creating potential security risks for users.
Affected Version(s)
Home Assistant Core 0
