[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-CVE-2026-64824":7},{"stargazers_count":4,"fetched_at":5,"stale":6},7,"2026-07-21T09:16:04.996Z",true,{"id":8,"descriptions":9,"cisa":10,"weaknesses":11,"exploits":41,"aliases":51,"duplicate_of":10,"upstream":52,"downstream":53,"duplicates":54,"related":55,"reserved_at":10,"published_at":56,"modified_at":57,"state":58,"summary":59,"references_raw":65,"kevs":95,"epss":10,"epss_history":96,"metrics":97,"affected":107},"CVE-2026-64824","Home Assistant Core before 2026.7.0 contains a path traversal vulnerability in the backup-restore function that allows attackers to write files to arbitrary absolute filesystem paths by supplying a crafted tar archive with a SYMTYPE entry containing a benign member name paired with an absolute linkname pointing outside the extraction directory. Because the official Docker image runs the Home Assistant process as root and the subsequent regular-file entry is written through the unvalidated symlink, attackers can achieve remote code execution by overwriting auto-imported Python paths such as site-packages/sitecustomize.py or custom component directories.",null,[12],{"_key":13,"id":13,"name":14,"description":15,"type":16,"status":17,"abstraction":18,"likelihood_of_exploit":19,"capec":20},"CWE-22","Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')","The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.","weakness","Stable","Base","High",[21,25,29,33,37],{"id":22,"name":23,"techniques":24},"CAPEC-126","Path Traversal",[],{"id":26,"name":27,"techniques":28},"CAPEC-64","Using Slashes and URL Encoding Combined to Bypass Validation Logic",[],{"id":30,"name":31,"techniques":32},"CAPEC-76","Manipulating Web Input to File System Calls",[],{"id":34,"name":35,"techniques":36},"CAPEC-78","Using Escaped Slashes in Alternate Encoding",[],{"id":38,"name":39,"techniques":40},"CAPEC-79","Using Slashes in Alternate Encoding",[],[42],{"_key":43,"name":44,"source":45,"url":46,"maturity":47,"reliability_score":48,"verified":49,"type":10,"platforms":50,"requires_auth":10,"exploitdb":10,"metasploit":10},"GITHUB_MERVINPRAISON_PRAISONAI","Praisonai","github","https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-8w9j-hc3g-3g7f","poc",0.3,false,[],[],[],[],[],[],"2026-07-21T15:39:52.162Z","2026-07-21T17:19:07.002Z","PUBLISHED",{"cisa_kev":49,"cisa_ransomware":49,"cisa_vendor":10,"epss_severity":10,"epss_score":10,"severity":60,"severity_score":61,"severity_version":62,"severity_source":63,"severity_vector":64,"severity_status":58},"critical",9.3,"v4.0","cve.org","CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H",[66,71,76,81,86,91],{"url":67,"sources":68,"tags":69},"https://github.com/home-assistant/core/releases/tag/2026.6.0",[63],[70],"Release Notes",{"url":72,"sources":73,"tags":74},"https://github.com/home-assistant/core/pull/172252",[63],[75],"Issue Tracking",{"url":77,"sources":78,"tags":79},"https://github.com/home-assistant/core/commit/1e457600f1093c15e1325742d03e2b76498c79c1",[63],[80],"Patch",{"url":82,"sources":83,"tags":84},"https://www.vulncheck.com/advisories/home-assistant-core-symlink-path-traversal-rce-via-backup-restore",[63],[85],"Third Party Advisory",{"url":87,"sources":88,"tags":89},"https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-78r8-wwqv-r299",[63],[90],"Exploit",{"url":92,"sources":93,"tags":94},"https://github.com/home-assistant/core/releases/tag/2026.7.0",[63],[70],[],[],[98],{"source":63,"cvss_v2_0":10,"cvss_v3_0":10,"cvss_v3_1":99,"cvss_v4_0":105},{"baseScore":100,"baseSeverity":101,"vectorString":102,"impactScore":103,"exploitabilityScore":104},8.4,"HIGH","CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H",10,4.4,{"baseScore":61,"baseSeverity":106,"vectorString":64,"impactScore":10,"exploitabilityScore":10},"CRITICAL",[108],{"ecosystem":10,"name":109,"vendor":110,"product":111,"cpe_part":112,"purl_type":10,"purl_namespace":10,"purl_name":10,"source":10,"versions":113},"Home Assistant Core","home-assistant","home assistant core","a",[114,118],{"version":115,"is_range":6,"range_type":63,"version_start":10,"version_start_type":10,"version_end":116,"version_end_type":117,"fixed_in":10},"\u003C 2026.6.0","2026.6.0","excluding",{"version":119,"is_range":6,"range_type":63,"version_start":10,"version_start_type":10,"version_end":120,"version_end_type":117,"fixed_in":10},"\u003C 2026.7.0","2026.7.0"]