Impact
A flaw in Home Assistant Core’s Shelly integration allows an attacker who can modify a Shelly device’s thumb field to inject arbitrary HTML content via a data URI bearing a text/html MIME type. This unsanctioned content is served through the media player proxy endpoint with a Content‑Type of text/html, enabling script execution within the Home Assistant web origin. Successful exploitation could allow an attacker to steal session tokens stored in local storage and perform authenticated calls to sensitive service endpoints such as locks, alarms, and covers.
Affected Systems
Any instance of Home Assistant Core running a version earlier than 2026.5.4 is vulnerable. This includes deployments on all platforms where Home Assistant Core 2026.5.3 or earlier is in use. The vulnerability is tied to the Shelly integration, so systems that have enabled Shelly devices are at risk.
Risk and Exploitability
The CVSS score is 2.1, indicating a low severity, and the EPSS score is less than 1%, underscoring a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. The most likely attack vector is an attacker with network access to a Shelly device or the ability to influence the thumb field locally; no publicly disclosed exploit code is known. Because the flaw involves client‑side script execution, exploitation requires that the victim access the Home Assistant web interface where the injected payload is rendered.
OpenCVE Enrichment