Cross-Site Scripting in Home Assistant Core's Shelly Integration
CVE-2026-64823

2.1LOW

Key Information:

Vendor
CVE Published:
21 July 2026

What is CVE-2026-64823?

A cross-site scripting vulnerability exists in the Shelly integration of Home Assistant Core prior to version 2026.5.4. This vulnerability allows attackers, who gain control of the thumb field from a Shelly device, to serve arbitrary HTML content by providing a data URI with text/html content type. The lack of validation against an image-only allowlist enables the media player proxy endpoint to respond with attacker-controlled content, which can lead to the theft of session tokens from local storage. Furthermore, this vulnerability can allow unauthorized interactions with sensitive service endpoints, creating potential security risks for users.

Affected Version(s)

Home Assistant Core 0

References

CVSS V4

Score:
2.1
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Harish Kolla (@Har1sh-k)
.