Path Traversal Vulnerability in Home Assistant Core by Home Assistant
CVE-2026-64825

9CRITICAL

Key Information:

Vendor
CVE Published:
21 July 2026

What is CVE-2026-64825?

Home Assistant Core versions prior to 2026.6.0 are susceptible to a path traversal vulnerability. This flaw allows unauthenticated attackers to write arbitrary files on the host filesystem. The vulnerability can be exploited during the initial onboarding process, where an attacker can upload a specially crafted backup archive. By manipulating the 'name' field in the backup's backup.json file, attackers can specify an absolute path, circumventing the intended backup directory prefix. This can lead to unauthorized file creation and potentially grant full filesystem access, especially if the application runs with root privileges.

Affected Version(s)

Home Assistant Core 0

References

CVSS V4

Score:
9
Severity:
CRITICAL
Confidentiality:
None
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Harish Kolla (@Har1sh-k)
.