ZDI-CAN-28429: ZDI-26-561: (Pwn2Own) Home Assistant Green go2rtc Command Injection Remote Code Execution Vulnerability
Published Aug 12, 2026
·Updated
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Home Assistant Green. An attacker must first obtain the ability to access the device's localhost interface. The ZDI has assigned a CVSS rating of 7.5.
Affected Software
1 affected component
Home Assistant Green
Event History
Aug 12, 2026
Advisory Published
via ZDI·05:00 AM
Data Sourced
via ZDI·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-CAN-28429?
ZDI-CAN-28429 has a CVSS rating of 7.5, indicating a high severity level.
2
What software is affected by ZDI-CAN-28429?
ZDI-CAN-28429 affects Home Assistant Green installations.
3
How do I fix ZDI-CAN-28429?
To mitigate ZDI-CAN-28429, ensure that your Home Assistant Green installation is updated to the latest version that addresses this vulnerability.
4
What type of attack does ZDI-CAN-28429 allow?
ZDI-CAN-28429 allows network-adjacent attackers to execute arbitrary code through command injection.
5
What must an attacker do to exploit ZDI-CAN-28429?
An attacker must gain access to the device's localhost interface to exploit ZDI-CAN-28429.