Vulnerabilities (CVE)

Filtered by vendor Home-assistant
Filtered by product Home-assistant-js-websocket
Angry Yack Logo
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-41896 1 Home-assistant 2 Home-assistant, Home-assistant-js-websocket 2024-11-21 N/A 7.1 HIGH
Home assistant is an open source home automation. Whilst auditing the frontend code to identify hidden parameters, Cure53 detected `auth_callback=1`, which is leveraged by the WebSocket authentication logic in tandem with the `state` parameter. The state parameter contains the `hassUrl`, which is subsequently utilized to establish a WebSocket connection. This behavior permits an attacker to create a malicious Home Assistant link with a modified state parameter that forces the frontend to connect ...

Show More