{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/tags/home-assistant/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.3,"id":"CVE-2026-64825"},{"cvss":8.4,"id":"CVE-2026-64824"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Home Assistant Core \u003c 2026.6.0"],"_cs_severities":["critical"],"_cs_tags":["vulnerability","path-traversal","home-assistant","rce","unauthenticated","initial-access"],"_cs_type":"advisory","_cs_vendors":["Home Assistant"],"content_html":"\u003cp\u003eA critical path traversal vulnerability, identified as CVE-2026-64825, affects Home Assistant Core versions prior to 2026.6.0. This flaw allows unauthenticated attackers to write arbitrary files to any directory on the host filesystem during the initial onboarding process. Attackers exploit this by uploading a specially crafted backup archive. Within this archive, the \u003ccode\u003ebackup.json\u003c/code\u003e file's 'name' field is modified to include an absolute path. The vulnerability lies in how Home Assistant handles this path with \u003ccode\u003epathlib.Path.__truediv__\u003c/code\u003e, causing the intended backup directory prefix to be ignored. This allows attacker-controlled content to be placed at arbitrary locations, potentially leading to full filesystem compromise. If the Home Assistant process operates with root privileges, this can escalate to full system control. The vulnerability's high CVSS v3.1 base score of 9.3 underscores its severe impact, enabling unauthenticated remote attackers to gain significant control over affected systems.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn unauthenticated attacker identifies a Home Assistant Core instance that is undergoing its initial onboarding configuration.\u003c/li\u003e\n\u003cli\u003eThe attacker crafts a malicious backup archive, ensuring it contains a specially modified \u003ccode\u003ebackup.json\u003c/code\u003e file.\u003c/li\u003e\n\u003cli\u003eInside the \u003ccode\u003ebackup.json\u003c/code\u003e file, the 'name' field is manipulated to specify an absolute path on the target filesystem (e.g., \u003ccode\u003e/etc/passwd\u003c/code\u003e or a web server root for remote code execution).\u003c/li\u003e\n\u003cli\u003eThe attacker uploads this specially crafted backup archive through the Home Assistant onboarding web interface, leveraging the legitimate backup restore functionality.\u003c/li\u003e\n\u003cli\u003eHome Assistant Core begins processing the uploaded archive, parsing the \u003ccode\u003ebackup.json\u003c/code\u003e file.\u003c/li\u003e\n\u003cli\u003eDue to the path traversal vulnerability in \u003ccode\u003epathlib.Path.__truediv__\u003c/code\u003e, the application discards the expected backup directory prefix and interprets the 'name' field's absolute path directly.\u003c/li\u003e\n\u003cli\u003eThe attacker-controlled content from the backup archive is then written to the arbitrary absolute path specified, leading to an unauthenticated arbitrary file write.\u003c/li\u003e\n\u003cli\u003eIf the Home Assistant process is running with root privileges, this arbitrary file write can be leveraged for privilege escalation or remote code execution, resulting in full system compromise.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-64825 results in unauthenticated arbitrary file write capabilities on the host filesystem. This critical vulnerability allows attackers to place malicious files, such as web shells, startup scripts, or configuration files, in sensitive system directories. If the Home Assistant process is running with elevated privileges, typically root on Linux systems, attackers can achieve privilege escalation, leading to full system compromise. The potential impact includes remote code execution, unauthorized data access, system alteration, and the establishment of persistent backdoors. While specific victim numbers are not provided, all unpatched Home Assistant Core instances exposed during their initial onboarding window are at risk of complete takeover.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePatch CVE-2026-64825 immediately by upgrading all Home Assistant Core instances to version 2026.6.0 or later.\u003c/li\u003e\n\u003cli\u003eEnsure Home Assistant instances are not publicly exposed during the initial onboarding window, as this is the primary vector for exploitation of this vulnerability.\u003c/li\u003e\n\u003cli\u003eMonitor \u003ccode\u003ewebserver\u003c/code\u003e logs for suspicious POST requests to backup or onboarding related endpoints, especially if an anomalous number of such requests occur or if requests contain unusual file sizes/types for backup archives.\u003c/li\u003e\n\u003cli\u003eImplement endpoint detection and response (EDR) solutions to monitor for unexpected file creations or modifications by the Home Assistant process (\u003ccode\u003efile_event\u003c/code\u003e, \u003ccode\u003eprocess_creation\u003c/code\u003e log sources) in sensitive system directories (e.g., \u003ccode\u003e/etc/\u003c/code\u003e, web root directories), which would indicate post-exploitation activity.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-21T16:31:40Z","date_published":"2026-07-21T16:30:46Z","id":"https://feed.craftedsignal.io/briefs/2026-07-home-assistant-pathtraversal/","summary":"A critical path traversal vulnerability, CVE-2026-64825, in Home Assistant Core versions before 2026.6.0 allows unauthenticated attackers to write arbitrary files to any directory on the host filesystem by uploading a crafted backup archive during the initial onboarding window, potentially leading to full system compromise with root privileges.","title":"Home Assistant Core Path Traversal Vulnerability (CVE-2026-64825)","url":"https://feed.craftedsignal.io/briefs/2026-07-home-assistant-pathtraversal/"}],"language":"en","title":"CraftedSignal Threat Feed - Home-Assistant","version":"https://jsonfeed.org/version/1.1"}