THREAT OPS › Threat News › [GHSA] GHSA-vv4j-m4vr-f3g6 (high) — ESPHome Device Builder Dashboard: Unauthenticated dashboard access via the HA add-on ingress site bound to all interfaces
[GHSA] GHSA-vv4j-m4vr-f3g6 (high) — ESPHome Device Builder Dashboard: Unauthenticated dashboard access via the HA add-on ingress site bound to all interfaces
GHSA-vv4j-m4vr-f3g6 Severity: high CVE: CVE-2026-59177
ESPHome Device Builder Dashboard: Unauthenticated dashboard access via the HA add-on ingress site bound to all interfaces
## Summary
On the Home Assistant add-on, the dashboard serves a trusted ingress site that skips authentication because the supervisor authenticates the request upstream. That site was binding `0.0.0.0`. The add-on runs i
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- CVE-2026-59177cve
- https://esphome.io/guides/security_best_practices/url
Original source: https://github.com/advisories/GHSA-vv4j-m4vr-f3g6