Junglewise Threat Intelligence

CVE-2026-64824: Home Assistant Core path traversal in backup-restore function

CVE-2026-64824 · Severity: high · CVSS 8.4 · Published 2026-07-21

Technologies: Home Assistant Core. Vendors: Home Assistant.

Executive brief

Home Assistant Core, a popular open-source home automation platform, is vulnerable to a security flaw in its backup and restore feature. An attacker with administrative access could upload a specially crafted backup file to gain full control over the underlying system. This could lead to the theft of sensitive data, disruption of home automation services, or the installation of malicious software.

Technical details

A path traversal vulnerability exists in the backup-restore function of Home Assistant Core due to improper validation of symlinks within tar archives. An attacker with high privileges can provide a crafted tar archive containing a SYMTYPE entry with an absolute linkname pointing outside the extraction directory. Because the official Docker image runs as root, subsequent file entries written through these unvalidated symlinks allow the attacker to overwrite critical system files. This can be leveraged for remote code execution by overwriting Python paths like site-packages/sitecustomize.py. The issue was fixed in version 2026.6.0 by implementing Python's built-in tarfile 'tar' filter to validate link targets.

Affected products

  • Home Assistant Home Assistant Core before 2026.6.0

Timeline

  • 2026-05-26: patched: Pull request to harden tar extraction merged
  • 2026-06-03: advisory: Release 2026.6.0 published
  • 2026-07-21: disclosed: CVE published to NVD

References