Home Assistant FFmpeg Flaw Lets Attackers Steal Supervisor Tokens and Execute Code as Root
Assistant’s FFmpeg integration recently came under scrutiny after researchers demonstrated that unsafe argument handling in the Wyoming Assist satellite feature could be exploited to steal Supervisor tokens and ultimately execute commands as root on the host system. The issue arises not from FFmpeg’s core parsing logic but rather from how Assistant incorporates attacker-controlled […]
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
