homeassistant is vulnerable to Cross-Site Scripting (XSS)
47
Medium Risk
The Shelly integration's media image proxy serves the bytes referenced by a device-controlled thumb field without checking the content type against an image allowlist. An attacker who controls a paired Shelly device can supply a data: URI with a text/html content type, causing the media player proxy endpoint to return attacker-controlled HTML under the Home Assistant web origin. Script in that response runs in the trusted origin and can steal session tokens from local storage and call authenticated service endpoints such as locks, alarms, and covers. The fix validates the MIME type of the thumb data URI so only image content is served through the proxy.
You are affected if you are using a version that falls within the vulnerable range and you use the Shelly integration with a media player device whose reported media metadata can include an untrusted thumb data URI.
homeassistant is vulnerable to Cross-Site Scripting (XSS) in versions 2026.5.0 - 2026.5.3.
Upgrade the homeassistant library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant