Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-64824— Home Assistant Core < 2026.7.0 Symlink Path Traversal RCE via backup-restore

Quick assessment

Affected
home-assistant Home Assistant Core
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

home-assistant Home Assistant Core是home-assistant社区的一款智能家居自动化平台。 home-assistant Home Assistant Core 2026.7.0之前版本存在路径遍历漏洞,该漏洞源于备份恢复功能中存在路径遍历问题,可能导致攻击者通过提供包含SYMTYPE条目的特制tar存档,将文件写入任意绝对文件系统路径。

CVSS 8.4 · High EPSS 0.80% · P55

Affected Version Matrix 1

VendorProduct Version RangeStatus
home-assistant Home Assistant Core < 2026.7.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-64824

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Home Assistant Core < 2026.7.0 Symlink Path Traversal RCE via backup-restore
Source: CVE Program / CVE List V5
Vulnerability Description
Home Assistant Core before 2026.7.0 contains a path traversal vulnerability in the backup-restore function that allows attackers to write files to arbitrary absolute filesystem paths by supplying a crafted tar archive with a SYMTYPE entry containing a benign member name paired with an absolute linkname pointing outside the extraction directory. Because the official Docker image runs the Home Assistant process as root and the subsequent regular-file entry is written through the unvalidated symlink, attackers can achieve remote code execution by overwriting auto-imported Python paths such as site-packages/sitecustomize.py or custom component directories.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Source: CVE Program / CVE List V5
Vulnerability Title
home-assistant Home Assistant Core 路径遍历漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
home-assistant Home Assistant Core是home-assistant社区的一款智能家居自动化平台。 home-assistant Home Assistant Core 2026.7.0之前版本存在路径遍历漏洞,该漏洞源于备份恢复功能中存在路径遍历问题,可能导致攻击者通过提供包含SYMTYPE条目的特制tar存档,将文件写入任意绝对文件系统路径。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
home-assistant Home Assistant Core 0 ~ 2026.7.0 -

II. Public POCs for CVE-2026-64824

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-64824

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-64824 (2)

Vendor Advisories for CVE-2026-64824 (1)

Vendor Pages for CVE-2026-64824 (2)

Same Patch Batch · home-assistant · 2026-07-21 · 3 CVEs total

CVE-2026-64825 9.3 CRITICAL Home Assistant Core < 2026.6.0 Path Traversal File Write via Backup Upload
CVE-2026-64823 4.7 MEDIUM Home Assistant Core < 2026.5.4 XSS via Shelly media_player.py thumb URI

IV. Related Vulnerabilities

V. Comments for CVE-2026-64824

No comments yet


Leave a comment