Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
10.0
CVE-2023-27482: RootIO Supervisor may let attackers run code
CVE-2023-27482 · published 3 days ago
Summary
The Supervisor component used in Alpine 3.19 can be tricked into running malicious code, which could give an attacker control over the system. This risk has been fixed in newer releases of the Supervisor package. Upgrade to the latest Supervisor version as soon as possible to protect your environment.
What to do
- Update alpine rootio-supervisor to version 4.2.5-r40074.
- Update supervisor to version 4.2.5-r40075.
- Update rootio-supervisor to version 4.2.5-r40075.
- Update home-assistant home-assistant to version 2023.3.0 or later.
- Update home-assistant supervisor to version 2023.03.1 or later.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| Root:Alpine:3.19 | alpine | rootio-supervisor |
< 4.2.5-r40074 Fix: upgrade to 4.2.5-r40074
|
| Root:Alpine:3.19 | – | supervisor |
< 4.2.5-r40075 Fix: upgrade to 4.2.5-r40075
|
| Root:Alpine:3.19 | – | rootio-supervisor |
< 4.2.5-r40075 Fix: upgrade to 4.2.5-r40075
|
| – | home-assistant | home-assistant |
< 2023.3.0 cpe:2.3:a:home-assistant:home-assistant:*:*:*:*:*:*:*:* |
| – | home-assistant | supervisor |
< 2023.03.1 cpe:2.3:a:home-assistant:supervisor:*:*:*:*:*:*:*:* |
Original advisory text
CVE-2023-27482 in supervisor - Patched by Root
Root has patched CVE-2023-27482 in the supervisor package for Root:Alpine:3.19. Multiple fixed versions available.
References
- https://github.com/elttam/publications/blob/master/writeups/home-assistant/super...
- https://github.com/home-assistant/core/security/advisories/GHSA-2j8f-h4mr-qr25 Vendor Advisory
- https://www.elttam.com/blog/pwnassistant/
- https://www.home-assistant.io/blog/2023/03/08/supervisor-security-disclosure/ Issue Tracking Vendor Advisory
Internet-facing
3 days
Internal
60 days
- Not known to be exploited
- Can be exploited automatically
- Gives an attacker full control
Severity
10.0
Critical
Type
CWE-287Improper Authentication
Timeline
Published29 Sep 2026
Updated30 Sep 2026
First seen30 Mar 2026
Track software like this
Free during beta