- Sources: primary
- Summary: elttam describes user input reaching an ffmpeg
-i argument in Home Assistant, which leaked the supervisor token. The concat and subfile pseudo-protocols keep the path exploitable even when the input validates as a URL. elttam researched the issue against Home Assistant Core 2026.5.4 and states an official patch was released in Home Assistant Core 2026.6.2. The fix works only when -protocol_whitelist is placed before -i. - Why it matters: URL validation is not sufficient to make an ffmpeg input argument safe, and argument order decides whether the mitigation applies.
send feedback on this story