ESPHome disclosed multiple vulnerabilities in its dashboard component that exposed authenticated users to arbitrary file access and stored cross-site scripting, with the most severe issue allowing remote attackers to read and write files under the configuration directory through the "edit configuration file" API. The path traversal flaw, tracked as CVE-2024-27081 / GHSA-8p25-3q46-8q2p, affected version 2023.12.9 and could expose esphome.json, firmware source code, Wi-Fi credentials, fallback hotspot credentials, OTA passwords, and API encryption keys. In command-line installations, attackers could also modify Python scripts used during firmware compilation and flashing, creating a path to remote code execution on the host running the dashboard.
A separate stored XSS bug, CVE-2024-27287, affected versions from 2023.12.9 through 2024.2.1 and stemmed from the /edit endpoint returning unsanitized user-controlled content as HTML. An authenticated attacker could inject JavaScript into a configuration file and trigger execution when another authenticated user opened a crafted /edit?configuration= link, enabling actions in the victim's session, access to sensitive data, configuration tampering, and firmware flashing on managed boards; the report also noted insufficient cookie protections that could aid session theft. ESPHome patched the file-write issue in version 2024.2.1 and the XSS issue in 2024.2.2, and the advisories said chaining these flaws with additional weaknesses could lead to unauthenticated remote code execution against the machine hosting the dashboard.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
ESPHome publicly disclosed CVE-2024-27287, detailing a stored XSS issue that could let an authenticated attacker execute JavaScript in another authenticated user's session via a crafted configuration file. Successful exploitation could enable actions on behalf of the victim, access to sensitive information, configuration changes, and firmware flashing on managed boards.
ESPHome proposed a patch for CVE-2024-27287, a stored cross-site scripting vulnerability in the dashboard edit configuration file API, and the fix was validated the same day. The flaw affected versions from 2023.12.9 up to but not including 2024.2.2.
ESPHome published a security advisory for CVE-2024-27081 describing authenticated arbitrary file access in the dashboard component and warning that chaining with other flaws could enable unauthenticated remote code execution. The advisory credited the Spike Reply Cybersecurity Team for reporting the issue.
ESPHome fixed CVE-2024-27081, a path traversal issue in the dashboard edit configuration API affecting version 2023.12.9. The patch was made on 2024-02-22 and released in ESPHome 2024.2.1, addressing authenticated arbitrary file read/write that could lead to remote code execution.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
lessonsec.com
Open sourcelessonsec.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.