Vendor
critical
advisory
Home Assistant Core Path Traversal Vulnerability (CVE-2026-64825)
2 TTPs 2 CVEsA critical path traversal vulnerability, CVE-2026-64825, in Home Assistant Core versions before 2026.6.0 allows unauthenticated attackers to write arbitrary files to any directory on the host filesystem by uploading a crafted backup archive during the initial onboarding window, potentially leading to full system compromise with root privileges.
Home Assistant Core < 2026.6.0
vulnerability
path-traversal
home-assistant
rce
unauthenticated
initial-access
2t
2c
high
threat
CVE-2021-47942: Home Assistant Community Store (HACS) Path Traversal Vulnerability
2 rules 1 TTP 1 CVEHome Assistant Community Store (HACS) 1.10.0 is vulnerable to a path traversal, allowing unauthenticated attackers to read sensitive files by traversing directories via the /hacsfiles/ endpoint, leading to potential account takeover.
Home Assistant Community Store
path-traversal
account-takeover
hacs
cve-2021-47942
2r
1t
1c