homeassistant is vulnerable to Path Traversal
84
High Risk
The backup restore function extracts uploaded tar archives without safely resolving symbolic links. A crafted archive can pair a benign member name with a symlink entry whose linkname is an absolute path pointing outside the extraction directory, so a following regular-file entry is written through the unvalidated symlink to an arbitrary absolute location. Because the official container image runs the process as root, an attacker can overwrite auto-imported Python paths such as sitecustomize.py or custom component files and achieve remote code execution. The fix stops using the fully trusted extraction filter and applies the standard tar filter so symlink and absolute-path members are no longer honored.
You are affected if you are using a version that falls within the vulnerable range and you restore a backup archive that originates from an untrusted source.
homeassistant is vulnerable to Path Traversal in versions 2024.12.0 - 2026.6.4.
Upgrade the homeassistant library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant