CVE-2026-64825Critical· 9.3▾ MidnightHome Assistant Core vulnerable to Path Traversal via backup upload during onboarding
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 51.2 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 14.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.5%
0.5% → 0.6%
Home Assistant Core before 2026.6.0 contains a path traversal vulnerability that allows unauthenticated attackers to write arbitrary files to any directory on the host filesystem by uploading a crafted backup archive during the initial onboarding window. Attackers can manipulate the 'name' field inside the uploaded archive's backup.json to supply an absolute path, causing pathlib.Path.truediv to discard the configured backup directory prefix and write attacker-controlled content to arbitrary locations, with full filesystem access when the process runs as root.
homeassistant < 2026.6.0Upgrade to a patched release:
homeassistant 2026.6.0Connected by shared product, vendor, weakness, or advisory.
CVE-2023-41893Medium· 4.3Home Assistant vulnerable to account takeover via auth_callback login
CVE-2026-33044LowHome Assistant has stored XSS in Map-card through malicious device name
CVE-2025-65713MediumHome Assistant Core before is vulnerable to Directory Traversal
CVE-2025-62172HighHome Assistant has Stored XSS vulnerability in Energy dashboard from Energy Entity Name
CVE-2025-25305High· 7.0Home Assistant does not correctly validate SSL for outgoing requests in core and used libs
CVE-2023-50715Medium· 4.3User accounts disclosed to unauthenticated actors on the LAN