Binding to an Unrestricted IP Address Affecting esphome-device-builder package, versions [,1.0.10)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Proof of Concept

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PYTHON-ESPHOMEDEVICEBUILDER-20158944
  • published27 Sept 2026
  • disclosed9 Sept 2026
  • creditUnknown

Introduced: 9 Sep 2026

NewCVE-2026-59177  (opens in a new tab)
CWE-1327  (opens in a new tab)

How to fix?

Upgrade esphome-device-builder to version 1.0.10 or higher.

Overview

esphome-device-builder is an ESPHome Device Builder

Affected versions of this package are vulnerable to Binding to an Unrestricted IP Address via the dashboard process. An attacker can gain full control over the application environment, including executing arbitrary code and accessing or modifying sensitive files, by sending unauthenticated requests from the local network to the exposed ingress port. #

Workaround

This vulnerability can be mitigated by restricting access to the add-on's ingress port at the network layer, such as implementing firewall rules to allow only the Home Assistant host and supervisor to connect, and ensuring the host resides on a trusted LAN segment.

CVSS Base Scores

version 4.0
version 3.1