← Vulnerability feed

Vulnerability record · CVE-2023-41896 · published 19 October 2023

CVE-2023-41896: Home-assistant insufficient verification of data authenticity vulnerability

Home Assistant · Home Assistant

Home assistant is an open source home automation. Whilst auditing the frontend code to identify hidden parameters, Cure53 detected `auth_callback=1`, which is leveraged by the WebSocket authentication logic in tandem with the `state` parameter. The state parameter contains the `hassUrl`, which is subsequently utilized to establish a WebSocket connection. This behavior permits an attacker to create a malicious Home Assistant link with a modified state parameter that forces the frontend to connect to an alternative WebSocket backend. Henceforth, the attacker can spoof any WebSocket responses and trigger cross site scripting (XSS). Since the XSS is executed on the actual Home Assistant frontend domain, it can connect to the real Home Assistant backend, which essentially represents a comprehensive takeover scenario. Permitting the site to be iframed by other origins, as discussed in GHSA-935v-rmg9-44mw, renders this exploit substantially covert since a malicious website can obfuscate the compromise strategy in the background. However, even without this, the attacker can still send the `auth_callback` link directly to the victim user. To mitigate this issue, Cure53 advises modifying the WebSocket code’s authentication flow. An optimal implementation in this regard would not trust the `hassUrl` passed in by a GET parameter. Cure53 must stipulate the significant time required of the Cure53 consultants to identify an XSS vector, despite holding full control over the WebSocket responses. In many areas, data from the WebSocket was properly sanitized, which hinders post-exploitation. The audit team eventually detected the `js_url` for custom panels, though generally, the frontend exhibited reasonable security hardening. This issue has been addressed in Home Assistant Core version 2023.8.0 and in the npm package home-assistant-js-websocket in version 8.2.0. Users are advised to upgrade. There are no known workarounds for this vulnerability.

9.0 CVSS 3.1 Critical EPSS 0.27% · top 82.7% CWE-345 · Insufficient verification of data authenticity
9.0CVSS 3.1 base score
0.27%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

Home assistant is an open source home automation. Whilst auditing the frontend code to identify hidden parameters, Cure53 detected `auth_callback=1`, which is leveraged by the WebSocket authentication logic in tandem with the `state` parameter. The state parameter contains the `hassUrl`, which is subsequently utilized to establish a WebSocket connection. This behavior permits an attacker to create a malicious Home Assistant link with a modified state parameter that forces the frontend to connect to an alternative WebSocket backend. Henceforth, the attacker can spoof any WebSocket responses and trigger cross site scripting (XSS). Since the XSS is executed on the actual Home Assistant frontend domain, it can connect to the real Home Assistant backend, which essentially represents a comprehensive takeover scenario. Permitting the site to be iframed by other origins, as discussed in GHSA-935v-rmg9-44mw, renders this exploit substantially covert since a malicious website can obfuscate the compromise strategy in the background. However, even without this, the attacker can still send the `auth_callback` link directly to the victim user. To mitigate this issue, Cure53 advises modifying the WebSocket code’s authentication flow. An optimal implementation in this regard would not trust the `hassUrl` passed in by a GET parameter. Cure53 must stipulate the significant time required of the Cure53 consultants to identify an XSS vector, despite holding full control over the WebSocket responses. In many areas, data from the WebSocket was properly sanitized, which hinders post-exploitation. The audit team eventually detected the `js_url` for custom panels, though generally, the frontend exhibited reasonable security hardening. This issue has been addressed in Home Assistant Core version 2023.8.0 and in the npm package home-assistant-js-websocket in version 8.2.0. Users are advised to upgrade. There are no known workarounds for this vulnerability.

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-41896 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2023-27482Home Assistant Supervisor authentication bypass via APIHome Assistant Supervisor 2023.01.1 and older contains an improper authentication flaw (CWE-287) that lets a remote attacker bypass authentication an…EPSS 72%analysed9.6CVE-2023-41895Home-assistant cross-site scripting vulnerabilityHome assistant is an open source home automation. The Home Assistant login page allows users to use their local Home Assistant credentials and log in…EPSS 0.67%9.6CVE-2023-41897Home-assistant clickjacking vulnerabilityHome assistant is an open source home automation. Home Assistant server does not set any HTTP security headers, including the X-Frame-Options header,…EPSS 0.95%7.6CVE-2026-54317Home-assistant information exposure vulnerabilityHome Assistant is open source home automation software that puts local control and privacy first. Prior to 2026.6.0, the Konnected integration regist…EPSS 0.31%7.5CVE-2020-36517Home-assistant observable discrepancy vulnerabilityAn information leak in Nabu Casa Home Assistant Operating System and Home Assistant Supervised 2022.03 allows a DNS operator to gain knowledge about …EPSS 2.9%7.5CVE-2018-21019Home-assistant information exposure vulnerabilityHome Assistant before 0.67.0 was vulnerable to an information disclosure that allowed an unauthenticated attacker to read the application's error log…EPSS 1.7%7.3CVE-2026-33045Home-assistant cross-site scripting vulnerabilityHome Assistant is open source home automation software that puts local control and privacy first. Starting in version 2025.02 and prior to version 20…EPSS 0.25%7.3CVE-2026-33044Home-assistant cross-site scripting vulnerabilityHome Assistant is open source home automation software that puts local control and privacy first. Starting in version 2020.02 and prior to version 20…EPSS 0.28%

Source: NIST National Vulnerability Database (record CVE-2023-41896), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.