Home Assistant Ffmpeg Flaw Lets Attackers Steal Supervisor Tokens And Execute Code As Root
A newly disclosed critical argument-injection vulnerability in Home Assistant’s Wyoming protocol integration allowed attackers to read arbitrary local files, including sensitive environment variables such as SUPERVISOR_TOKEN, ultimately enabling root-level command execution on the host system.
The flaw was discovered while Jia Hao hunted for high-impact attack chain primitives rather than complete exploit chains, building on their prior 2023 audit of Home Assistant’s pre-authentication attack surface.
The vulnerability resided in the announce service of Home Assistant’s Wyoming Assist satellite integration, where the attacker-controlled media_id parameter was passed directly to ffmpeg as the -i command argument without adequate sanitization.
Home Assistant FFmpeg Flaw
Jia Hao found that while the media_id field underwent URL validation with a scheme blocklist to prevent SSRF attacks against local Home Assistant addresses, ffmpeg’s pseudo-protocols such as concat:, file:, and subfile: were not on this blocklist.
This oversight allowed arbitrary ffmpeg protocol strings to reach the subprocess, opening a path for reading files such as/proc/self/environ.
Exploitation faced a significant obstacle: ffmpeg’s output arguments enforced a raw PCM audio transcoding format, meaning input lacking a valid audio header would fail silently.
Researchers overcame this by chaining subfile: and concat: pseudo-protocols to splice precise byte ranges from /bin/go2rtc, a binary present by default on Home Assistant OS, synthesizing a fake audio header.
This crafted header tricked ffmpeg into accepting the target file as valid audio input, causing it to transcode and stream the file’s actual contents, including the coveted SUPERVISOR_TOKEN, to an attacker-controlled Wyoming satellite endpoint.
Successful exploitation required two conditions: attacker control of a paired Wyoming Assist satellite (requiring initial Layer 2 network access during mDNS-based pairing) and possession of a valid Home Assistant API token to interact with the announce endpoint.
Once the SUPERVISOR_TOKEN was exfiltrated, attackers could exploit Home Assistant Supervisor APIs to execute root commands on the host, thereby achieving a complete compromise of the smart home system.
Jia Hao demonstrated the exploit by emulating a Wyoming satellite via an mDNS broadcast, pairing it with a target Home Assistant instance, and then triggering the announce service with a specially crafted media_id payload.
It contained a spliced header chain that terminates at/proc/self/environ. The proof-of-concept successfully exfiltrated the HASSIO_TOKEN and SUPERVISOR_TOKEN environment variables in cleartext.
The vulnerability affected Home Assistant Core version 2026.5.4 and was patched in version 2026.6.2 by adding ffmpeg’s -protocol_whitelist argument, restricted to http, https, file, tcp, and tls protocols, and placing it before the -i argument to ensure enforcement.
A unit test was added to verify correct argument ordering, since ffmpeg applies options sequentially to subsequent files.
Despite the fix, Jia Hao noted that the patch could be strengthened further by sanitizing input before values are passed to subprocess commands, even when the input appears benign.
The case underscores broader risks in how applications integrate open-source components like ffmpeg, where dangerous usage patterns can introduce exploitable primitives independent of upstream parsing vulnerabilities.
Cut SOC investigation blind spots and contain threats earlier to reduce response costs and business disruption with ANY.RUN.
The post Home Assistant FFmpeg Flaw Lets Attackers Steal Supervisor Tokens and Execute Code as Root appeared first on Cyber Security News.
Popular Products
-
Fake Pregnancy Test$61.56$30.78 -
Anti-Slip Safety Handle for Elderly S...$57.56$28.78 -
Toe Corrector Orthotics$41.56$20.78 -
Waterproof Trauma Medical First Aid Kit$169.56$84.78 -
Rescue Zip Stitch Kit$109.56$54.78