home-assistant Home Assistant Core是home-assistant社区的一款智能家居自动化平台。 home-assistant Home Assistant Core 2026.6.0之前版本存在路径遍历漏洞,该漏洞源于路径遍历问题,允许未经身份验证的攻击者在初始引导窗口期间上传特制的备份存档,操作备份存档中backup.json的'name'字段以提供绝对路径,导致路径前缀被丢弃,向任意目录写入任意文件。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| home-assistant | Home Assistant Core | < 2026.6.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| home-assistant | Home Assistant Core | 0 ~ 2026.6.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-64824 | 8.4 HIGH | Home Assistant Core < 2026.7.0 Symlink Path Traversal RCE via backup-restore |
| CVE-2026-64823 | 4.7 MEDIUM | Home Assistant Core < 2026.5.4 XSS via Shelly media_player.py thumb URI |
No comments yet