Collected research
PwnAssistant - Controlling /home’s via a Home Assistant RCE
PwnAssistant - Controlling /home's via a Home Assistant RCE
Audits Home Assistant’s authentication exceptions and traces proxy requests through route matching, decoding and URL normalization. Double-decoding, whitespace-removal and trusted-header variants expose Supervisor APIs, while successive bypasses show why middleware fixes must agree on both the target path and the provenance of security-sensitive headers.
Record
- Document
- PwnAssistant - Controlling /home's via a Home Assistant RCE
- Researcher
- Joseph Surin and Victor Kahan
- Published by
- elttam
- Topic
- Server
In the archive
Related sources
- Home Assistant Supervisor Authentication Bypass Advisory Code
- Signed URL parameter tampering advisory Code
- Home Assistant CVE-2023-27482 advisory Advisory
- Media source arbitrary file write advisory Code
Tags
This page is the archive's own catalogue record. The research is the work of Joseph Surin and Victor Kahan, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .