Compass Security demonstrated an unauthenticated exploit chain at Pwn2Own Cork 2025 that achieved root access on a Home Assistant Green host through the Music Assistant add-on 2.6.0. The add-on exposed its web interface on port 8095 without authentication, allowing playlist-update requests to be abused for arbitrary file writes. Researchers converted this primitive into Python code execution in the Music Assistant container by planting a malicious .pth file, a Python site-configuration mechanism processed during interpreter startup.
Because the container used host networking, the researchers captured plaintext internal Home Assistant Supervisor API traffic and stole a privileged Home Assistant Core bearer token. They used the token to install a malicious privileged add-on with Docker API access, then escaped through Docker to obtain root on Home Assistant OS. Music Assistant 2.7.0 remediates the initial attack path by requiring authentication on port 8095 and rejecting playlist file-path updates for filesystem providers; operators should upgrade and review exposed add-ons, privileged tokens, and Docker-capable integrations.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
At Pwn2Own Cork 2025, researchers demonstrated an unauthenticated exploit chain against a Home Assistant Green device, progressing from the Music Assistant add-on to root control of the Home Assistant OS host. The successful entry earned $20,000 and four Master of Pwn points.
Music Assistant version 2.7.0 added authentication to its port 8095 web interface and rejected filesystem-provider playlist file-path updates, mitigating the unauthenticated access and arbitrary-file-write primitives used in the exploit chain.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.