ESPHome Device Builder: Dashboard Authentication Issue on Upgrade
- Severity
- HIGH
- Affected component
- esphome-device-builder (pypi)
- Affected versions
- < 1.0.10 or >= 0.1.0b10, <= 0.1.0b10 or >= 0.1.0b100, <= 0.1.0b100 or >= 0.1.0b101, <= 0.1.0b101 or >= 0.1.0b102, <= 0.1.0b102 or >= 0.1.0b103, <= 0.1.0b103 or >= 0.1.0b104, <= 0.1.0b104 or >= 0.1.0b105, <= 0.1.0b105 or >= 0.1.0b106, <= 0.1.0b106 or >= 0.1.0b107, <= 0.1.0b107 or >= 0.1.0b108, <= 0.1.0b108 or >= 0.1.0b109, <= 0.1.0b109 or >= 0.1.0b11, <= 0.1.0b11 or >= 0.1.0b110, <= 0.1.0b110 or >= 0.1.0b111, <= 0.1.0b111 or >= 0.1.0b112, <= 0.1.0b112 or >= 0.1.0b113, <= 0.1.0b113 or >= 0.1.0b114, <= 0.1.0b114 or >= 0.1.0b115, <= 0.1.0b115 or >= 0.1.0b116, <= 0.1.0b116 or >= 0.1.0b117, <= 0.1.0b117 or >= 0.1.0b118, <= 0.1.0b118 or >= 0.1.0b119, <= 0.1.0b119 or >= 0.1.0b12, <= 0.1.0b12 or >= 0.1.0b13, <= 0.1.0b13 or >= 0.1.0b14, <= 0.1.0b14 or >= 0.1.0b15, <= 0.1.0b15 or >= 0.1.0b16, <= 0.1.0b16 or >= 0.1.0b17, <= 0.1.0b17 or >= 0.1.0b18, <= 0.1.0b18 or >= 0.1.0b19, <= 0.1.0b19 or >= 0.1.0b20, <= 0.1.0b20 or >= 0.1.0b21, <= 0.1.0b21 or >= 0.1.0b22, <= 0.1.0b22 or >= 0.1.0b23, <= 0.1.0b23 or >= 0.1.0b24, <= 0.1.0b24 or >= 0.1.0b25, <= 0.1.0b25 or >= 0.1.0b26, <= 0.1.0b26 or >= 0.1.0b27, <= 0.1.0b27 or >= 0.1.0b28, <= 0.1.0b28 or >= 0.1.0b29, <= 0.1.0b29 or >= 0.1.0b30, <= 0.1.0b30 or >= 0.1.0b31, <= 0.1.0b31 or >= 0.1.0b32, <= 0.1.0b32 or >= 0.1.0b33, <= 0.1.0b33 or >= 0.1.0b34, <= 0.1.0b34 or >= 0.1.0b35, <= 0.1.0b35 or >= 0.1.0b36, <= 0.1.0b36 or >= 0.1.0b37, <= 0.1.0b37 or >= 0.1.0b38, <= 0.1.0b38 or >= 0.1.0b39, <= 0.1.0b39 or >= 0.1.0b40, <= 0.1.0b40 or >= 0.1.0b41, <= 0.1.0b41 or >= 0.1.0b42, <= 0.1.0b42 or >= 0.1.0b43, <= 0.1.0b43 or >= 0.1.0b44, <= 0.1.0b44 or >= 0.1.0b45, <= 0.1.0b45 or >= 0.1.0b46, <= 0.1.0b46 or >= 0.1.0b47, <= 0.1.0b47 or >= 0.1.0b48, <= 0.1.0b48 or >= 0.1.0b49, <= 0.1.0b49 or >= 0.1.0b50, <= 0.1.0b50 or >= 0.1.0b51, <= 0.1.0b51 or >= 0.1.0b52, <= 0.1.0b52 or >= 0.1.0b53, <= 0.1.0b53 or >= 0.1.0b54, <= 0.1.0b54 or >= 0.1.0b55, <= 0.1.0b55 or >= 0.1.0b56, <= 0.1.0b56 or >= 0.1.0b57, <= 0.1.0b57 or >= 0.1.0b58, <= 0.1.0b58 or >= 0.1.0b59, <= 0.1.0b59 or >= 0.1.0b60, <= 0.1.0b60 or >= 0.1.0b61, <= 0.1.0b61 or >= 0.1.0b62, <= 0.1.0b62 or >= 0.1.0b63, <= 0.1.0b63 or >= 0.1.0b64, <= 0.1.0b64 or >= 0.1.0b65, <= 0.1.0b65 or >= 0.1.0b66, <= 0.1.0b66 or >= 0.1.0b67, <= 0.1.0b67 or >= 0.1.0b68, <= 0.1.0b68 or >= 0.1.0b69, <= 0.1.0b69 or >= 0.1.0b70, <= 0.1.0b70 or >= 0.1.0b71, <= 0.1.0b71 or >= 0.1.0b72, <= 0.1.0b72 or >= 0.1.0b73, <= 0.1.0b73 or >= 0.1.0b74, <= 0.1.0b74 or >= 0.1.0b75, <= 0.1.0b75 or >= 0.1.0b76, <= 0.1.0b76 or >= 0.1.0b77, <= 0.1.0b77 or >= 0.1.0b78, <= 0.1.0b78 or >= 0.1.0b79, <= 0.1.0b79 or >= 0.1.0b80, <= 0.1.0b80 or >= 0.1.0b81, <= 0.1.0b81 or >= 0.1.0b82, <= 0.1.0b82 or >= 0.1.0b83, <= 0.1.0b83 or >= 0.1.0b84, <= 0.1.0b84 or >= 0.1.0b85, <= 0.1.0b85 or >= 0.1.0b86, <= 0.1.0b86 or >= 0.1.0b87, <= 0.1.0b87 or >= 0.1.0b88, <= 0.1.0b88 or >= 0.1.0b89, <= 0.1.0b89 or >= 0.1.0b90, <= 0.1.0b90 or >= 0.1.0b91, <= 0.1.0b91 or >= 0.1.0b92, <= 0.1.0b92 or >= 0.1.0b93, <= 0.1.0b93 or >= 0.1.0b94, <= 0.1.0b94 or >= 0.1.0b95, <= 0.1.0b95 or >= 0.1.0b96, <= 0.1.0b96 or >= 0.1.0b97, <= 0.1.0b97 or >= 0.1.0b98, <= 0.1.0b98 or >= 0.1.0b99, <= 0.1.0b99 or >= 1.0.0, <= 1.0.0 or >= 1.0.1, <= 1.0.1 or >= 1.0.10b1, <= 1.0.10b1 or >= 1.0.10b2, <= 1.0.10b2 or >= 1.0.2b1, <= 1.0.2b1 or >= 1.0.2b2, <= 1.0.2b2 or >= 1.0.2b3, <= 1.0.2b3 or >= 1.0.2b4, <= 1.0.2b4 or >= 1.0.3, <= 1.0.3 or >= 1.0.4, <= 1.0.4 or >= 1.0.5, <= 1.0.5 or >= 1.0.6, <= 1.0.6 or >= 1.0.7, <= 1.0.7 or >= 1.0.8, <= 1.0.8 or >= 1.0.9, <= 1.0.9 or < 1.0.10 or >= 0.1.0b10, <= 0.1.0b10 or >= 0.1.0b100, <= 0.1.0b100 or >= 0.1.0b101, <= 0.1.0b101 or >= 0.1.0b102, <= 0.1.0b102 or >= 0.1.0b103, <= 0.1.0b103 or >= 0.1.0b104, <= 0.1.0b104 or >= 0.1.0b105, <= 0.1.0b105 or >= 0.1.0b106, <= 0.1.0b106 or >= 0.1.0b107, <= 0.1.0b107 or >= 0.1.0b108, <= 0.1.0b108 or >= 0.1.0b109, <= 0.1.0b109 or >= 0.1.0b11, <= 0.1.0b11 or >= 0.1.0b110, <= 0.1.0b110 or >= 0.1.0b111, <= 0.1.0b111 or >= 0.1.0b112, <= 0.1.0b112 or >= 0.1.0b113, <= 0.1.0b113 or >= 0.1.0b114, <= 0.1.0b114 or >= 0.1.0b115, <= 0.1.0b115 or >= 0.1.0b116, <= 0.1.0b116 or >= 0.1.0b117, <= 0.1.0b117 or >= 0.1.0b118, <= 0.1.0b118 or >= 0.1.0b119, <= 0.1.0b119 or >= 0.1.0b12, <= 0.1.0b12 or >= 0.1.0b13, <= 0.1.0b13 or >= 0.1.0b14, <= 0.1.0b14 or >= 0.1.0b15, <= 0.1.0b15 or >= 0.1.0b16, <= 0.1.0b16 or >= 0.1.0b17, <= 0.1.0b17 or >= 0.1.0b18, <= 0.1.0b18 or >= 0.1.0b19, <= 0.1.0b19 or >= 0.1.0b20, <= 0.1.0b20 or >= 0.1.0b21, <= 0.1.0b21 or >= 0.1.0b22, <= 0.1.0b22 or >= 0.1.0b23, <= 0.1.0b23 or >= 0.1.0b24, <= 0.1.0b24 or >= 0.1.0b25, <= 0.1.0b25 or >= 0.1.0b26, <= 0.1.0b26 or >= 0.1.0b27, <= 0.1.0b27 or >= 0.1.0b28, <= 0.1.0b28 or >= 0.1.0b29, <= 0.1.0b29 or >= 0.1.0b30, <= 0.1.0b30 or >= 0.1.0b31, <= 0.1.0b31 or >= 0.1.0b32, <= 0.1.0b32 or >= 0.1.0b33, <= 0.1.0b33 or >= 0.1.0b34, <= 0.1.0b34 or >= 0.1.0b35, <= 0.1.0b35 or >= 0.1.0b36, <= 0.1.0b36 or >= 0.1.0b37, <= 0.1.0b37 or >= 0.1.0b38, <= 0.1.0b38 or >= 0.1.0b39, <= 0.1.0b39 or >= 0.1.0b40, <= 0.1.0b40 or >= 0.1.0b41, <= 0.1.0b41 or >= 0.1.0b42, <= 0.1.0b42 or >= 0.1.0b43, <= 0.1.0b43 or >= 0.1.0b44, <= 0.1.0b44 or >= 0.1.0b45, <= 0.1.0b45 or >= 0.1.0b46, <= 0.1.0b46 or >= 0.1.0b47, <= 0.1.0b47 or >= 0.1.0b48, <= 0.1.0b48 or >= 0.1.0b49, <= 0.1.0b49 or >= 0.1.0b50, <= 0.1.0b50 or >= 0.1.0b51, <= 0.1.0b51 or >= 0.1.0b52, <= 0.1.0b52 or >= 0.1.0b53, <= 0.1.0b53 or >= 0.1.0b54, <= 0.1.0b54 or >= 0.1.0b55, <= 0.1.0b55 or >= 0.1.0b56, <= 0.1.0b56 or >= 0.1.0b57, <= 0.1.0b57 or >= 0.1.0b58, <= 0.1.0b58 or >= 0.1.0b59, <= 0.1.0b59 or >= 0.1.0b60, <= 0.1.0b60 or >= 0.1.0b61, <= 0.1.0b61 or >= 0.1.0b62, <= 0.1.0b62 or >= 0.1.0b63, <= 0.1.0b63 or >= 0.1.0b64, <= 0.1.0b64 or >= 0.1.0b65, <= 0.1.0b65 or >= 0.1.0b66, <= 0.1.0b66 or >= 0.1.0b67, <= 0.1.0b67 or >= 0.1.0b68, <= 0.1.0b68 or >= 0.1.0b69, <= 0.1.0b69 or >= 0.1.0b70, <= 0.1.0b70 or >= 0.1.0b71, <= 0.1.0b71 or >= 0.1.0b72, <= 0.1.0b72 or >= 0.1.0b73, <= 0.1.0b73 or >= 0.1.0b74, <= 0.1.0b74 or >= 0.1.0b75, <= 0.1.0b75 or >= 0.1.0b76, <= 0.1.0b76 or >= 0.1.0b77, <= 0.1.0b77 or >= 0.1.0b78, <= 0.1.0b78 or >= 0.1.0b79, <= 0.1.0b79 or >= 0.1.0b80, <= 0.1.0b80 or >= 0.1.0b81, <= 0.1.0b81 or >= 0.1.0b82, <= 0.1.0b82 or >= 0.1.0b83, <= 0.1.0b83 or >= 0.1.0b84, <= 0.1.0b84 or >= 0.1.0b85, <= 0.1.0b85 or >= 0.1.0b86, <= 0.1.0b86 or >= 0.1.0b87, <= 0.1.0b87 or >= 0.1.0b88, <= 0.1.0b88 or >= 0.1.0b89, <= 0.1.0b89 or >= 0.1.0b90, <= 0.1.0b90 or >= 0.1.0b91, <= 0.1.0b91 or >= 0.1.0b92, <= 0.1.0b92 or >= 0.1.0b93, <= 0.1.0b93 or >= 0.1.0b94, <= 0.1.0b94 or >= 0.1.0b95, <= 0.1.0b95 or >= 0.1.0b96, <= 0.1.0b96 or >= 0.1.0b97, <= 0.1.0b97 or >= 0.1.0b98, <= 0.1.0b98 or >= 0.1.0b99, <= 0.1.0b99 or >= 1.0.0, <= 1.0.0 or >= 1.0.1, <= 1.0.1 or >= 1.0.10b1, <= 1.0.10b1 or >= 1.0.10b2, <= 1.0.10b2 or >= 1.0.2b1, <= 1.0.2b1 or >= 1.0.2b2, <= 1.0.2b2 or >= 1.0.2b3, <= 1.0.2b3 or >= 1.0.2b4, <= 1.0.2b4 or >= 1.0.3, <= 1.0.3 or >= 1.0.4, <= 1.0.4 or >= 1.0.5, <= 1.0.5 or >= 1.0.6, <= 1.0.6 or >= 1.0.7, <= 1.0.7 or >= 1.0.8, <= 1.0.8 or >= 1.0.9, <= 1.0.9
- Patched version
- Not yet available
An early warning has been issued regarding the ESPHome Device Builder package. It appears to silently disable dashboard authentication upon upgrade due to changes in environment variable names.
What happened
The ESPHome Device Builder package, available on PyPI, is reported to have an issue where it silently disables dashboard authentication after an upgrade. This is due to a change in the names of environment variables used for authentication. As a result, the dashboard becomes accessible to anyone who can reach its port, posing a significant security risk.
The vulnerability affects a wide range of versions of the esphome-device-builder package. Users of versions less than 1.0.10 or greater than or equal to 0.1.0b10 and less than or equal to various beta versions are potentially at risk. The issue has been tracked under GHSA-RRXG-G2PF-6HH4 and CVE-2026-59178.
What to do about it
- Check your current version of the esphome-device-builder package against the affected version ranges provided.
- If you are using an affected version, migrate to the new environment variable names ($ESPHOME_USERNAME and $ESPHOME_PASSWORD) to maintain dashboard authentication.
- Consider upgrading to a non-affected version if available. Monitor the provided sources for updates on patched versions.
- If no official fix has been published yet, continue to monitor the situation and sources for updates.
How 0Day would have caught this
esphome-device-builder is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.
Frequently asked questions
Am I affected?
You are potentially affected if you are using a version of esphome-device-builder less than 1.0.10 or greater than or equal to 0.1.0b10 and less than or equal to various beta versions.
What should I do right now?
Check your version against the affected ranges and migrate to the new environment variable names if necessary. Monitor sources for updates on a fix.
Has this been exploited in the wild?
There is no confirmed report of this vulnerability being exploited in the wild at this time.