Path Traversal Vulnerability in Home Assistant Core
CVE-2026-64824
9.3CRITICAL
What is CVE-2026-64824?
Home Assistant Core versions prior to 2026.6.0 are vulnerable to a path traversal flaw in the backup-restore functionality. This vulnerability enables attackers to craft a malicious tar archive that can manipulate the extraction process, leading to potential remote code execution. By exploiting this vulnerability, attackers can overwrite essential Python files and custom directories due to the unvalidated symbolic links, particularly when the Home Assistant process is run with root permissions in the official Docker image. This presents significant risks for users who utilize this application for smart home management.
Affected Version(s)
Home Assistant Core 0
