Path Traversal Vulnerability in Home Assistant Core by Home Assistant
CVE-2026-64825
9CRITICAL
What is CVE-2026-64825?
Home Assistant Core versions prior to 2026.6.0 are susceptible to a path traversal vulnerability. This flaw allows unauthenticated attackers to write arbitrary files on the host filesystem. The vulnerability can be exploited during the initial onboarding process, where an attacker can upload a specially crafted backup archive. By manipulating the 'name' field in the backup's backup.json file, attackers can specify an absolute path, circumventing the intended backup directory prefix. This can lead to unauthorized file creation and potentially grant full filesystem access, especially if the application runs with root privileges.
Affected Version(s)
Home Assistant Core 0
