Vulnerabilities & Exploits · Web App Attack

Music Assistant Add-on Escalated to Home Assistant Root

Compass Security says it found an unauthenticated remote code execution flaw in the Music Assistant add-on for Home Assistant and used it to pivot to root on the underlying Home Assistant OS. Music Assistant 2.7.0 now adds authentication and blocks file uploads.

The weakness was in the add-on’s own web interface: because it did not require a login, the researchers could drive the app’s functions directly, then move from code execution inside the add-on to full host access. That means the danger was not limited to the add-on process itself; the platform boundary between an add-on and the operating system did not hold.

For Home Assistant operators, especially on self-hosted systems like Home Assistant Green, the exposure sits at the add-on web UI and what it can reach behind it. If that panel can run with host-adjacent privileges, patching the add-on is also closing a path to the OS, not just fixing an isolated app.

1 source · 1 day ago

Timeline

Sources

Part of the PlainSec briefing for 2026-10-03

Every edition of this story: Music Assistant Add-on Escalated to Home Assistant Root

More from today