A AegiFlow
CRITICALCVSS 9.0EPSS 0.5%

CVE-2026-64825

CVE-2026-64825 updated by NVD

Published
2026-07-21
Modified
2026-08-13
EPSS percentile
39%
Sources
github-advisory, nvd

Summary

Home Assistant Core before 2026.6.0 contains a path traversal vulnerability that allows unauthenticated attackers to write arbitrary files to any directory on the host filesystem by uploading a crafted backup archive during the initial onboarding window. Attackers can manipulate the 'name' field inside the uploaded archive's backup.json to supply an absolute path, causing pathlib.Path.__truediv__ to discard the configured backup directory prefix and write attacker-controlled content to arbitrary locations, with full filesystem access when the process runs as root.

Affected packages

EcosystemPackageAffected versionsFixed versions
PyPIhomeassistant2026.6.0

Remediation: Upgrade to 2026.6.0 or later.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

Includes data from the National Vulnerability Database (NIST). NVD data is in the public domain; this page is not endorsed by NIST.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.

EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.