HIGH 8.8 GitHub
CVE-2026-59177
ESPHome Device Builder Dashboard: Unauthenticated dashboard access via the HA add-on ingress site bound to all interfaces
## Summary
On the Home Assistant add-on, the dashboard serves a trusted ingress site that skips authentication because the supervisor authenticates the request upstream. That site was binding `0.0.0.0`. The add-on runs in host network mode for mDNS, so binding all interfaces also bound the host's LAN interface, and any device on the local network could reach `http://<ha-ip>:<ingress_port>/` and get the full dashboard with no credentials.
## Details
The HA add-on ingress site is intentionally
Affected Products
- pip/esphome-device-builder < 1.0.10
References
- https://github.com/advisories/GHSA-vv4j-m4vr-f3g6
- https://github.com/esphome/device-builder/security/advisories/GHSA-vv4j-m4vr-f3g6
- https://github.com/esphome/device-builder/pull/1565
- https://github.com/esphome/device-builder/commit/b6387db3f8bf1d3df5771f40e9856b959ae4f6a1
This high severity vulnerability with a CVSS score of 8.8 was published on 2026-09-09 via GitHub. Affected: pip/esphome-device-builder < 1.0.10.
vulnfeed aggregates 13138 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.