PT-2021-19401 · Unknown · Home Assistant
Oriel Goel
·
Published
2021-01-21
·
Updated
2026-04-23
·
CVE-2021-3152
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Home Assistant versions prior to 2021.1.3
Description
The issue is related to a lack of protection against directory-traversal attacks in custom integrations. It is noted that the vendor views the vulnerability as being in custom integrations written by third parties, rather than in Home Assistant itself. However, Home Assistant has a security update that addresses this situation.
Recommendations
For versions prior to 2021.1.3, update to version 2021.1.3 or later to address the issue. As a temporary workaround, consider restricting access to custom integrations until the update is applied.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Home Assistant