home-assistant Home Assistant Core是home-assistant社区的一款智能家居自动化平台。 home-assistant Home Assistant Core 2026.7.0之前版本存在路径遍历漏洞,该漏洞源于备份恢复功能中存在路径遍历问题,可能导致攻击者通过提供包含SYMTYPE条目的特制tar存档,将文件写入任意绝对文件系统路径。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| home-assistant | Home Assistant Core | < 2026.7.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| home-assistant | Home Assistant Core | 0 ~ 2026.7.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-64825 | 9.3 CRITICAL | Home Assistant Core < 2026.6.0 Path Traversal File Write via Backup Upload |
| CVE-2026-64823 | 4.7 MEDIUM | Home Assistant Core < 2026.5.4 XSS via Shelly media_player.py thumb URI |
No comments yet