PYPI · SEPTEMBER 2026 · EARLY WARNING

ESPHome Device Builder: Dashboard Authentication Issue on Upgrade

EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
Severity
HIGH
Affected component
esphome-device-builder (pypi)
Affected versions
< 1.0.10 or >= 0.1.0b10, <= 0.1.0b10 or >= 0.1.0b100, <= 0.1.0b100 or >= 0.1.0b101, <= 0.1.0b101 or >= 0.1.0b102, <= 0.1.0b102 or >= 0.1.0b103, <= 0.1.0b103 or >= 0.1.0b104, <= 0.1.0b104 or >= 0.1.0b105, <= 0.1.0b105 or >= 0.1.0b106, <= 0.1.0b106 or >= 0.1.0b107, <= 0.1.0b107 or >= 0.1.0b108, <= 0.1.0b108 or >= 0.1.0b109, <= 0.1.0b109 or >= 0.1.0b11, <= 0.1.0b11 or >= 0.1.0b110, <= 0.1.0b110 or >= 0.1.0b111, <= 0.1.0b111 or >= 0.1.0b112, <= 0.1.0b112 or >= 0.1.0b113, <= 0.1.0b113 or >= 0.1.0b114, <= 0.1.0b114 or >= 0.1.0b115, <= 0.1.0b115 or >= 0.1.0b116, <= 0.1.0b116 or >= 0.1.0b117, <= 0.1.0b117 or >= 0.1.0b118, <= 0.1.0b118 or >= 0.1.0b119, <= 0.1.0b119 or >= 0.1.0b12, <= 0.1.0b12 or >= 0.1.0b13, <= 0.1.0b13 or >= 0.1.0b14, <= 0.1.0b14 or >= 0.1.0b15, <= 0.1.0b15 or >= 0.1.0b16, <= 0.1.0b16 or >= 0.1.0b17, <= 0.1.0b17 or >= 0.1.0b18, <= 0.1.0b18 or >= 0.1.0b19, <= 0.1.0b19 or >= 0.1.0b20, <= 0.1.0b20 or >= 0.1.0b21, <= 0.1.0b21 or >= 0.1.0b22, <= 0.1.0b22 or >= 0.1.0b23, <= 0.1.0b23 or >= 0.1.0b24, <= 0.1.0b24 or >= 0.1.0b25, <= 0.1.0b25 or >= 0.1.0b26, <= 0.1.0b26 or >= 0.1.0b27, <= 0.1.0b27 or >= 0.1.0b28, <= 0.1.0b28 or >= 0.1.0b29, <= 0.1.0b29 or >= 0.1.0b30, <= 0.1.0b30 or >= 0.1.0b31, <= 0.1.0b31 or >= 0.1.0b32, <= 0.1.0b32 or >= 0.1.0b33, <= 0.1.0b33 or >= 0.1.0b34, <= 0.1.0b34 or >= 0.1.0b35, <= 0.1.0b35 or >= 0.1.0b36, <= 0.1.0b36 or >= 0.1.0b37, <= 0.1.0b37 or >= 0.1.0b38, <= 0.1.0b38 or >= 0.1.0b39, <= 0.1.0b39 or >= 0.1.0b40, <= 0.1.0b40 or >= 0.1.0b41, <= 0.1.0b41 or >= 0.1.0b42, <= 0.1.0b42 or >= 0.1.0b43, <= 0.1.0b43 or >= 0.1.0b44, <= 0.1.0b44 or >= 0.1.0b45, <= 0.1.0b45 or >= 0.1.0b46, <= 0.1.0b46 or >= 0.1.0b47, <= 0.1.0b47 or >= 0.1.0b48, <= 0.1.0b48 or >= 0.1.0b49, <= 0.1.0b49 or >= 0.1.0b50, <= 0.1.0b50 or >= 0.1.0b51, <= 0.1.0b51 or >= 0.1.0b52, <= 0.1.0b52 or >= 0.1.0b53, <= 0.1.0b53 or >= 0.1.0b54, <= 0.1.0b54 or >= 0.1.0b55, <= 0.1.0b55 or >= 0.1.0b56, <= 0.1.0b56 or >= 0.1.0b57, <= 0.1.0b57 or >= 0.1.0b58, <= 0.1.0b58 or >= 0.1.0b59, <= 0.1.0b59 or >= 0.1.0b60, <= 0.1.0b60 or >= 0.1.0b61, <= 0.1.0b61 or >= 0.1.0b62, <= 0.1.0b62 or >= 0.1.0b63, <= 0.1.0b63 or >= 0.1.0b64, <= 0.1.0b64 or >= 0.1.0b65, <= 0.1.0b65 or >= 0.1.0b66, <= 0.1.0b66 or >= 0.1.0b67, <= 0.1.0b67 or >= 0.1.0b68, <= 0.1.0b68 or >= 0.1.0b69, <= 0.1.0b69 or >= 0.1.0b70, <= 0.1.0b70 or >= 0.1.0b71, <= 0.1.0b71 or >= 0.1.0b72, <= 0.1.0b72 or >= 0.1.0b73, <= 0.1.0b73 or >= 0.1.0b74, <= 0.1.0b74 or >= 0.1.0b75, <= 0.1.0b75 or >= 0.1.0b76, <= 0.1.0b76 or >= 0.1.0b77, <= 0.1.0b77 or >= 0.1.0b78, <= 0.1.0b78 or >= 0.1.0b79, <= 0.1.0b79 or >= 0.1.0b80, <= 0.1.0b80 or >= 0.1.0b81, <= 0.1.0b81 or >= 0.1.0b82, <= 0.1.0b82 or >= 0.1.0b83, <= 0.1.0b83 or >= 0.1.0b84, <= 0.1.0b84 or >= 0.1.0b85, <= 0.1.0b85 or >= 0.1.0b86, <= 0.1.0b86 or >= 0.1.0b87, <= 0.1.0b87 or >= 0.1.0b88, <= 0.1.0b88 or >= 0.1.0b89, <= 0.1.0b89 or >= 0.1.0b90, <= 0.1.0b90 or >= 0.1.0b91, <= 0.1.0b91 or >= 0.1.0b92, <= 0.1.0b92 or >= 0.1.0b93, <= 0.1.0b93 or >= 0.1.0b94, <= 0.1.0b94 or >= 0.1.0b95, <= 0.1.0b95 or >= 0.1.0b96, <= 0.1.0b96 or >= 0.1.0b97, <= 0.1.0b97 or >= 0.1.0b98, <= 0.1.0b98 or >= 0.1.0b99, <= 0.1.0b99 or >= 1.0.0, <= 1.0.0 or >= 1.0.1, <= 1.0.1 or >= 1.0.10b1, <= 1.0.10b1 or >= 1.0.10b2, <= 1.0.10b2 or >= 1.0.2b1, <= 1.0.2b1 or >= 1.0.2b2, <= 1.0.2b2 or >= 1.0.2b3, <= 1.0.2b3 or >= 1.0.2b4, <= 1.0.2b4 or >= 1.0.3, <= 1.0.3 or >= 1.0.4, <= 1.0.4 or >= 1.0.5, <= 1.0.5 or >= 1.0.6, <= 1.0.6 or >= 1.0.7, <= 1.0.7 or >= 1.0.8, <= 1.0.8 or >= 1.0.9, <= 1.0.9 or < 1.0.10 or >= 0.1.0b10, <= 0.1.0b10 or >= 0.1.0b100, <= 0.1.0b100 or >= 0.1.0b101, <= 0.1.0b101 or >= 0.1.0b102, <= 0.1.0b102 or >= 0.1.0b103, <= 0.1.0b103 or >= 0.1.0b104, <= 0.1.0b104 or >= 0.1.0b105, <= 0.1.0b105 or >= 0.1.0b106, <= 0.1.0b106 or >= 0.1.0b107, <= 0.1.0b107 or >= 0.1.0b108, <= 0.1.0b108 or >= 0.1.0b109, <= 0.1.0b109 or >= 0.1.0b11, <= 0.1.0b11 or >= 0.1.0b110, <= 0.1.0b110 or >= 0.1.0b111, <= 0.1.0b111 or >= 0.1.0b112, <= 0.1.0b112 or >= 0.1.0b113, <= 0.1.0b113 or >= 0.1.0b114, <= 0.1.0b114 or >= 0.1.0b115, <= 0.1.0b115 or >= 0.1.0b116, <= 0.1.0b116 or >= 0.1.0b117, <= 0.1.0b117 or >= 0.1.0b118, <= 0.1.0b118 or >= 0.1.0b119, <= 0.1.0b119 or >= 0.1.0b12, <= 0.1.0b12 or >= 0.1.0b13, <= 0.1.0b13 or >= 0.1.0b14, <= 0.1.0b14 or >= 0.1.0b15, <= 0.1.0b15 or >= 0.1.0b16, <= 0.1.0b16 or >= 0.1.0b17, <= 0.1.0b17 or >= 0.1.0b18, <= 0.1.0b18 or >= 0.1.0b19, <= 0.1.0b19 or >= 0.1.0b20, <= 0.1.0b20 or >= 0.1.0b21, <= 0.1.0b21 or >= 0.1.0b22, <= 0.1.0b22 or >= 0.1.0b23, <= 0.1.0b23 or >= 0.1.0b24, <= 0.1.0b24 or >= 0.1.0b25, <= 0.1.0b25 or >= 0.1.0b26, <= 0.1.0b26 or >= 0.1.0b27, <= 0.1.0b27 or >= 0.1.0b28, <= 0.1.0b28 or >= 0.1.0b29, <= 0.1.0b29 or >= 0.1.0b30, <= 0.1.0b30 or >= 0.1.0b31, <= 0.1.0b31 or >= 0.1.0b32, <= 0.1.0b32 or >= 0.1.0b33, <= 0.1.0b33 or >= 0.1.0b34, <= 0.1.0b34 or >= 0.1.0b35, <= 0.1.0b35 or >= 0.1.0b36, <= 0.1.0b36 or >= 0.1.0b37, <= 0.1.0b37 or >= 0.1.0b38, <= 0.1.0b38 or >= 0.1.0b39, <= 0.1.0b39 or >= 0.1.0b40, <= 0.1.0b40 or >= 0.1.0b41, <= 0.1.0b41 or >= 0.1.0b42, <= 0.1.0b42 or >= 0.1.0b43, <= 0.1.0b43 or >= 0.1.0b44, <= 0.1.0b44 or >= 0.1.0b45, <= 0.1.0b45 or >= 0.1.0b46, <= 0.1.0b46 or >= 0.1.0b47, <= 0.1.0b47 or >= 0.1.0b48, <= 0.1.0b48 or >= 0.1.0b49, <= 0.1.0b49 or >= 0.1.0b50, <= 0.1.0b50 or >= 0.1.0b51, <= 0.1.0b51 or >= 0.1.0b52, <= 0.1.0b52 or >= 0.1.0b53, <= 0.1.0b53 or >= 0.1.0b54, <= 0.1.0b54 or >= 0.1.0b55, <= 0.1.0b55 or >= 0.1.0b56, <= 0.1.0b56 or >= 0.1.0b57, <= 0.1.0b57 or >= 0.1.0b58, <= 0.1.0b58 or >= 0.1.0b59, <= 0.1.0b59 or >= 0.1.0b60, <= 0.1.0b60 or >= 0.1.0b61, <= 0.1.0b61 or >= 0.1.0b62, <= 0.1.0b62 or >= 0.1.0b63, <= 0.1.0b63 or >= 0.1.0b64, <= 0.1.0b64 or >= 0.1.0b65, <= 0.1.0b65 or >= 0.1.0b66, <= 0.1.0b66 or >= 0.1.0b67, <= 0.1.0b67 or >= 0.1.0b68, <= 0.1.0b68 or >= 0.1.0b69, <= 0.1.0b69 or >= 0.1.0b70, <= 0.1.0b70 or >= 0.1.0b71, <= 0.1.0b71 or >= 0.1.0b72, <= 0.1.0b72 or >= 0.1.0b73, <= 0.1.0b73 or >= 0.1.0b74, <= 0.1.0b74 or >= 0.1.0b75, <= 0.1.0b75 or >= 0.1.0b76, <= 0.1.0b76 or >= 0.1.0b77, <= 0.1.0b77 or >= 0.1.0b78, <= 0.1.0b78 or >= 0.1.0b79, <= 0.1.0b79 or >= 0.1.0b80, <= 0.1.0b80 or >= 0.1.0b81, <= 0.1.0b81 or >= 0.1.0b82, <= 0.1.0b82 or >= 0.1.0b83, <= 0.1.0b83 or >= 0.1.0b84, <= 0.1.0b84 or >= 0.1.0b85, <= 0.1.0b85 or >= 0.1.0b86, <= 0.1.0b86 or >= 0.1.0b87, <= 0.1.0b87 or >= 0.1.0b88, <= 0.1.0b88 or >= 0.1.0b89, <= 0.1.0b89 or >= 0.1.0b90, <= 0.1.0b90 or >= 0.1.0b91, <= 0.1.0b91 or >= 0.1.0b92, <= 0.1.0b92 or >= 0.1.0b93, <= 0.1.0b93 or >= 0.1.0b94, <= 0.1.0b94 or >= 0.1.0b95, <= 0.1.0b95 or >= 0.1.0b96, <= 0.1.0b96 or >= 0.1.0b97, <= 0.1.0b97 or >= 0.1.0b98, <= 0.1.0b98 or >= 0.1.0b99, <= 0.1.0b99 or >= 1.0.0, <= 1.0.0 or >= 1.0.1, <= 1.0.1 or >= 1.0.10b1, <= 1.0.10b1 or >= 1.0.10b2, <= 1.0.10b2 or >= 1.0.2b1, <= 1.0.2b1 or >= 1.0.2b2, <= 1.0.2b2 or >= 1.0.2b3, <= 1.0.2b3 or >= 1.0.2b4, <= 1.0.2b4 or >= 1.0.3, <= 1.0.3 or >= 1.0.4, <= 1.0.4 or >= 1.0.5, <= 1.0.5 or >= 1.0.6, <= 1.0.6 or >= 1.0.7, <= 1.0.7 or >= 1.0.8, <= 1.0.8 or >= 1.0.9, <= 1.0.9
Patched version
Not yet available
GHSA-RRXG-G2PF-6HH4

An early warning has been issued regarding the ESPHome Device Builder package. It appears to silently disable dashboard authentication upon upgrade due to changes in environment variable names.

What happened

The ESPHome Device Builder package, available on PyPI, is reported to have an issue where it silently disables dashboard authentication after an upgrade. This is due to a change in the names of environment variables used for authentication. As a result, the dashboard becomes accessible to anyone who can reach its port, posing a significant security risk.

The vulnerability affects a wide range of versions of the esphome-device-builder package. Users of versions less than 1.0.10 or greater than or equal to 0.1.0b10 and less than or equal to various beta versions are potentially at risk. The issue has been tracked under GHSA-RRXG-G2PF-6HH4 and CVE-2026-59178.

What to do about it

How 0Day would have caught this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If esphome-device-builder is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Frequently asked questions

Am I affected?

You are potentially affected if you are using a version of esphome-device-builder less than 1.0.10 or greater than or equal to 0.1.0b10 and less than or equal to various beta versions.

What should I do right now?

Check your version against the affected ranges and migrate to the new environment variable names if necessary. Monitor sources for updates on a fix.

Has this been exploited in the wild?

There is no confirmed report of this vulnerability being exploited in the wild at this time.

Sources

Join the 0Day waitlist →

← Back to all threats