PT-2025-52771 · Home Assistant · Home Assistant Core

·

CVE-2025-65713

·

Published

2025-12-23

·

Updated

2026-07-07

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:H/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:P
Name of the Vulnerable Software and Affected Versions Home Assistant Core versions prior to 2025.8.0
Description The Downloader integration does not completely validate file paths when combining them, which creates a directory traversal issue. This allows unauthorized access to files outside the intended directory.
Recommendations Update to Home Assistant Core version 2025.8.0 or later.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-65713
GHSA-PP3G-XMM4-5CW9
PYSEC-2026-1454

Affected Products

Home Assistant Core