PT-2025-52771 · Home Assistant · Home Assistant Core

Atuin Automated Vulnerability Discovery Engine

+1

·

Published

2025-12-23

·

Updated

2025-12-26

·

CVE-2025-65713

CVSS v3.1

4.0

Medium

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Home Assistant Core versions prior to 2025.8.0
Description The Downloader integration does not completely validate file paths when combining them, which creates a directory traversal issue. This allows unauthorized access to files outside the intended directory.
Recommendations Update to Home Assistant Core version 2025.8.0 or later.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2025-65713
GHSA-PP3G-XMM4-5CW9

Affected Products

Home Assistant Core