Answer in brief
CVE-2026-64825 records a Critical severity (CVSS 9.0) vulnerability in Home Assistant Core < 2026.6.0 Path Traversal File Write via Backup Upload. The current sources do not mark it as known exploited. The current feed maps home-assistant/Home Assistant Core (generic), homeassistant (pip), homeassistant (pypi). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 9.0. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps home-assistant/Home Assistant Core (generic), homeassistant (pip), homeassistant (pypi). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| home-assistant/Home Assistant Coregeneric | * | Not reported |
| homeassistantpip | <2026.6.0 | 2026.6.0 |
| homeassistantpypi | >=0 <2026.6.0 | 2026.6.0 |
Published upstream
Jul 21, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Oct 8, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 13, 2026
Home Assistant Core before 2026.6.0 contains a path traversal vulnerability that allows unauthenticated attackers to write arbitrary files to any directory on the host filesystem by uploading a crafted backup archive during the initial onboarding window. Attackers can manipulate the 'name' field inside the uploaded archive's backup.json to supply an absolute path, causing pathlib.Path.__truediv__ to discard the configured backup directory prefix and write attacker-controlled content to arbitrary locations, with full filesystem access when the process runs as root.
Quoted source text, attributed separately from HOL analysis.