Researchers disclosed a Home Assistant vulnerability in the Wyoming integration's announce feature that let attackers abuse FFmpeg input handling to inject arguments and access local files. By leveraging FFmpeg pseudo-protocols such as file:, concat:, and subfile:, the attack could assemble synthetic audio streams from local byte ranges, enabling exfiltration of sensitive data including /proc/self/environ and the SUPERVISOR_TOKEN.
With the recovered supervisor token, an attacker could call Home Assistant's supervisor API and execute commands as root, potentially compromising both the Home Assistant instance and its host system. The attack required control of a paired Wyoming Assist satellite and a valid Home Assistant API token, making local network or previously established access a likely prerequisite. Home Assistant addressed the issue in Core 2026.6.2 by enforcing a strict FFmpeg protocol allowlist and applying it before the input argument to block parsing bypasses.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
Home Assistant fixed the vulnerability in Core version 2026.6.2 by adding a strict FFmpeg protocol allowlist and applying it before the input argument to block parsing bypasses. The patch addressed the file theft and root command execution path in the Wyoming integration's announce feature.
Researchers at elttam disclosed a vulnerability in Home Assistant's Wyoming integration that let attackers abuse FFmpeg input handling in the announce feature to read arbitrary local files and escalate to root command execution. The research showed pseudo-protocol abuse could expose sensitive data such as the SUPERVISOR_TOKEN and enable supervisor API access.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
4 references tracked. Mallory keeps watching after this page renders.
elttam.com
Open sourcecryptika.com
Open sourcecybersecuritynews.com
Open sourcereddit.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.