Advisory Database
  • Advisories
  • Dependency Scanning
  1. pypi
  2. ›
  3. homeassistant
  4. ›
  5. CVE-2026-64825

CVE-2026-64825: Home Assistant Core vulnerable to Path Traversal via backup upload during onboarding

July 21, 2026 (updated August 13, 2026)

Home Assistant Core before 2026.6.0 contains a path traversal vulnerability that allows unauthenticated attackers to write arbitrary files to any directory on the host filesystem by uploading a crafted backup archive during the initial onboarding window. Attackers can manipulate the ’name’ field inside the uploaded archive’s backup.json to supply an absolute path, causing pathlib.Path.truediv to discard the configured backup directory prefix and write attacker-controlled content to arbitrary locations, with full filesystem access when the process runs as root.

References

  • github.com/advisories/GHSA-5hxg-r395-fqxx
  • github.com/home-assistant/core/commit/567fe858289876b68b8162a77bd46e1e1af79752
  • github.com/home-assistant/core/pull/172368
  • github.com/home-assistant/core/releases/tag/2026.6.0
  • nvd.nist.gov/vuln/detail/CVE-2026-64825
  • www.vulncheck.com/advisories/home-assistant-core-path-traversal-file-write-via-backup-upload

Code Behaviors & Features

Detect and mitigate CVE-2026-64825 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 2026.6.0

Fixed versions

  • 2026.6.0

Solution

Upgrade to version 2026.6.0 or above.

Impact 9.3 CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:L

Learn more about CVSS

Weakness

  • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Source file

pypi/homeassistant/CVE-2026-64825.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Thu, 10 Sep 2026 00:20:03 +0000.