[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-CVE-2026-64825":7},{"stargazers_count":4,"fetched_at":5,"stale":6},7,"2026-07-21T09:16:04.996Z",true,{"id":8,"descriptions":9,"cisa":10,"weaknesses":11,"exploits":41,"aliases":42,"duplicate_of":10,"upstream":43,"downstream":44,"duplicates":45,"related":46,"reserved_at":10,"published_at":47,"modified_at":48,"state":49,"summary":50,"references_raw":57,"kevs":78,"epss":10,"epss_history":79,"metrics":80,"affected":89},"CVE-2026-64825","Home Assistant Core before 2026.6.0 contains a path traversal vulnerability that allows unauthenticated attackers to write arbitrary files to any directory on the host filesystem by uploading a crafted backup archive during the initial onboarding window. Attackers can manipulate the 'name' field inside the uploaded archive's backup.json to supply an absolute path, causing pathlib.Path.__truediv__ to discard the configured backup directory prefix and write attacker-controlled content to arbitrary locations, with full filesystem access when the process runs as root.",null,[12],{"_key":13,"id":13,"name":14,"description":15,"type":16,"status":17,"abstraction":18,"likelihood_of_exploit":19,"capec":20},"CWE-22","Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')","The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.","weakness","Stable","Base","High",[21,25,29,33,37],{"id":22,"name":23,"techniques":24},"CAPEC-126","Path Traversal",[],{"id":26,"name":27,"techniques":28},"CAPEC-64","Using Slashes and URL Encoding Combined to Bypass Validation Logic",[],{"id":30,"name":31,"techniques":32},"CAPEC-76","Manipulating Web Input to File System Calls",[],{"id":34,"name":35,"techniques":36},"CAPEC-78","Using Escaped Slashes in Alternate Encoding",[],{"id":38,"name":39,"techniques":40},"CAPEC-79","Using Slashes in Alternate Encoding",[],[],[],[],[],[],[],"2026-07-21T15:40:18.756Z","2026-07-21T17:15:20.162Z","PUBLISHED",{"cisa_kev":51,"cisa_ransomware":51,"cisa_vendor":10,"epss_severity":10,"epss_score":10,"severity":52,"severity_score":53,"severity_version":54,"severity_source":55,"severity_vector":56,"severity_status":49},false,"critical",9.3,"v3.1","cve.org","CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:L",[58,63,68,73],{"url":59,"sources":60,"tags":61},"https://github.com/home-assistant/core/releases/tag/2026.6.0",[55],[62],"Release Notes",{"url":64,"sources":65,"tags":66},"https://github.com/home-assistant/core/pull/172368",[55],[67],"Issue Tracking",{"url":69,"sources":70,"tags":71},"https://github.com/home-assistant/core/commit/567fe858289876b68b8162a77bd46e1e1af79752",[55],[72],"Patch",{"url":74,"sources":75,"tags":76},"https://www.vulncheck.com/advisories/home-assistant-core-path-traversal-file-write-via-backup-upload",[55],[77],"Third Party Advisory",[],[],[81],{"source":55,"cvss_v2_0":10,"cvss_v3_0":10,"cvss_v3_1":82,"cvss_v4_0":86},{"baseScore":53,"baseSeverity":83,"vectorString":56,"impactScore":84,"exploitabilityScore":85},"CRITICAL",7.8,10,{"baseScore":87,"baseSeverity":83,"vectorString":88,"impactScore":10,"exploitabilityScore":10},9,"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:L/SC:N/SI:H/SA:L",[90],{"ecosystem":10,"name":91,"vendor":92,"product":93,"cpe_part":94,"purl_type":10,"purl_namespace":10,"purl_name":10,"source":10,"versions":95},"Home Assistant Core","home-assistant","home assistant core","a",[96],{"version":97,"is_range":6,"range_type":55,"version_start":10,"version_start_type":10,"version_end":98,"version_end_type":99,"fixed_in":10},"\u003C 2026.6.0","2026.6.0","excluding"]