Path Traversal Vulnerability in Home Assistant Core
CVE-2026-64824

9.3CRITICAL

Key Information:

Vendor
CVE Published:
21 July 2026

What is CVE-2026-64824?

Home Assistant Core versions prior to 2026.6.0 are vulnerable to a path traversal flaw in the backup-restore functionality. This vulnerability enables attackers to craft a malicious tar archive that can manipulate the extraction process, leading to potential remote code execution. By exploiting this vulnerability, attackers can overwrite essential Python files and custom directories due to the unvalidated symbolic links, particularly when the Home Assistant process is run with root permissions in the official Docker image. This presents significant risks for users who utilize this application for smart home management.

Affected Version(s)

Home Assistant Core 0

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Harish Kolla (@Har1sh-k)
.