Later archive addition
PwnAssistant - Controlling /home’s via a Home Assistant RCE
Audits Home Assistant’s authentication exceptions and traces proxy requests through route matching, decoding and URL normalization. Double-decoding, whitespace-removal and trusted-header variants expose Supervisor APIs, while successive bypasses show why middleware fixes must agree on both the target path and the provenance of security-sensitive headers.
Record
- Researcher
- Joseph Surin and Victor Kahan
- Published by
- elttam
In the archive
Related sources
- Technical advisory
- Signed URL parameter tampering advisory
- Home Assistant CVE-2023-27482 advisory
- Media source arbitrary file write advisory
Tags
This page is the archive's own catalogue record. The research is the work of Joseph Surin and Victor Kahan, first published at the original source. Preserved copies are kept so the citation survives its host.