Indicator
Type cve · source NVD CVE
Enrichment by provider
Grouped attempts with latest status; expand for attempt history.
1 attempt · first 2026-07-21T21:49:12.059781Z · last 2026-07-21T21:49:12.059781Z
Not listed in CISA KEV (local)
Types: cisa_kev
1 attempt · first 2026-07-21T21:49:11.974393Z · last 2026-07-21T21:49:11.974393Z
EPSS unavailable (API or CVE id)
Types: epss
1 attempt · first 2026-07-21T21:49:12.063030Z · last 2026-07-21T21:49:12.063030Z
Home Assistant Core before 2026.6.0 contains a path traversal vulnerability that allows unauthenticated attackers to write arbitrary files to any directory on the host filesystem by uploading a crafted backup archive during the initial onboarding window. Attackers can manipulate the 'name' field inside the uploaded archive's backup.json to supply an absolute path, causing pathlib.Path.__truediv__
Types: nvd_local
CONTINUE INVESTIGATION
High-signal pivots without leaving the thread you started in search.
Structured pivots from local graph context.
See edges, pivots, and corroboration at a glance.
Full inspector with neighbor expansion.