UNKNOWN PyPI
Home Assistant Core before is vulnerable to Directory Traversal
GHSA-pp3g-xmm4-5cw9 · CVE-2025-65713 · PYSEC-2026-1454
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
Home Assistant Core before v2025.8.0 is vulnerable to Directory Traversal. The Downloader integration does not fully validate file paths during concatenation, leaving a path traversal vulnerability.
References
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2025-65713
- WEB https://github.com/home-assistant/core/pull/150046
- WEB https://gist.github.com/GenoWang/7359360285e0fe21a7a58d10ff71d032
- PACKAGE https://github.com/home-assistant/core
- WEB https://github.com/home-assistant/core/blob/a4d12694dae82f10e2ca9c524e44a22ab7dacf66/homeassistant/components/downloader/services.py#L32
- WEB https://github.com/home-assistant/core/blob/a4d12694dae82f10e2ca9c524e44a22ab7dacf66/homeassistant/util/__init__.py#L20
- WEB https://github.com/home-assistant/core/blob/a4d12694dae82f10e2ca9c524e44a22ab7dacf66/homeassistant/util/__init__.py#L32-L38
Ready to move
Start Securing
Free, no credit card | First findings in minutes