Home Assistant Core before is vulnerable to Directory Traversal
Moderate severity
GitHub Reviewed
Published
Dec 23, 2025
to the GitHub Advisory Database
•
Updated Dec 23, 2025
Description
Published by the National Vulnerability Database
Dec 23, 2025
Published to the GitHub Advisory Database
Dec 23, 2025
Reviewed
Dec 23, 2025
Last updated
Dec 23, 2025
Home Assistant Core before v2025.8.0 is vulnerable to Directory Traversal. The Downloader integration does not fully validate file paths during concatenation, leaving a path traversal vulnerability.
References