PT-2021-19401 · Unknown · Home Assistant

Oriel Goel

·

Published

2021-01-21

·

Updated

2026-04-23

·

CVE-2021-3152

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Home Assistant versions prior to 2021.1.3
Description The issue is related to a lack of protection against directory-traversal attacks in custom integrations. It is noted that the vendor views the vulnerability as being in custom integrations written by third parties, rather than in Home Assistant itself. However, Home Assistant has a security update that addresses this situation.
Recommendations For versions prior to 2021.1.3, update to version 2021.1.3 or later to address the issue. As a temporary workaround, consider restricting access to custom integrations until the update is applied.

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2021-3152

Affected Products

Home Assistant