CVE-CVE-2026-64824
Severity
HIGH
CVSS Score
8.4
Description
Home Assistant Core before 2026.7.0 contains a path traversal vulnerability in the backup-restore function that allows attackers to write files to arbitrary absolute filesystem paths by supplying a crafted tar archive with a SYMTYPE entry containing a benign member name paired with an absolute linkname pointing outside the extraction directory. Because the official Docker image runs the Home Assistant process as root and the subsequent regular-file entry is written through the unvalidated symlin...
PoCs for CVE-CVE-2026-64824
CVE-2026-64824-PoC
RCE
Python
0
Boreas37
2026-08-10