THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-vv4j-m4vr-f3g6 (high) — ESPHome Device Builder Dashboard: Unauthenticated dashboard access via the HA add-on ingress site bound to all interfaces

[GHSA] GHSA-vv4j-m4vr-f3g6 (high) — ESPHome Device Builder Dashboard: Unauthenticated dashboard access via the HA add-on ingress site bound to all interfaces

highgithub_advisoriesPublished 2026-09-09

GHSA-vv4j-m4vr-f3g6 Severity: high CVE: CVE-2026-59177

ESPHome Device Builder Dashboard: Unauthenticated dashboard access via the HA add-on ingress site bound to all interfaces

## Summary

On the Home Assistant add-on, the dashboard serves a trusted ingress site that skips authentication because the supervisor authenticates the request upstream. That site was binding `0.0.0.0`. The add-on runs i

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-vv4j-m4vr-f3g6