Home Assistant before 2021.1.3 lacks a protection layer against directory-traversal attacks in custom integrations, letting attackers access arbitrary files, exploit requires attacker to deploy malicious custom integration.
id: CVE-2021-3152
info:
name: Home Assistant HACS - Local File Inclusion
author: DhiyaneshDk
...