๐Ÿ” CVE Alert

CVE-2026-71259

HIGH 8.6

ESPHome external_components file:// Scheme Validation Bypass Leading to Remote Code Execution

CVSS Score
8.6
EPSS Score
0.0%
EPSS Percentile
0th

ESPHome through 2026.7.0-dev contains an operator-precedence bug in the cv.url() validator in esphome/config_validation.py: `if parsed.scheme and parsed.netloc or parsed.scheme == "file": return parsed.geturl()`. Because `and` binds tighter than `or`, any file: URI passes validation regardless of netloc. This validator gates the `url:` field of the external_components YAML directive's git source schema, which is passed to `git clone` (git supports file:// natively). A crafted `external_components` block with `url: "file:///attacker/repo"` clones an attacker-controlled local path, which is then added to Python's import machinery via ESPHome's component loader, executing arbitrary Python code when the YAML configuration is processed (e.g. via `esphome config`/`esphome run`).

CWE CWE-184
Vendor esphome
Product esphome
Published Aug 5, 2026
Last Updated Aug 5, 2026
Stay Ahead of the Next One

Get instant alerts for esphome esphome

Be the first to know when new high vulnerabilities affecting esphome esphome are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

esphome / esphome
0 โ‰ค 2026.7.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/esphome/esphome github.com: https://github.com/esphome/esphome/blob/dev/esphome/config_validation.py

Credits

Alibek Baxtiyorov