—
PYSEC-2026-1454
Home Assistant Core before is vulnerable to Directory Traversal
Quick fix
PYSEC-2026-1454 — homeassistant: upgrade to the fixed version with the command below.
pip install --upgrade 'homeassistant>=2025.8.0'Details
Home Assistant Core before v2025.8.0 is vulnerable to Directory Traversal. The Downloader integration does not fully validate file paths during concatenation, leaving a path traversal vulnerability.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/homeassistant
Introduced in:
0Fixed in: 2025.8.0Fix
pip install --upgrade 'homeassistant>=2025.8.0'References
- https://nvd.nist.gov/vuln/detail/CVE-2025-65713[ADVISORY]
- https://github.com/home-assistant/core/pull/150046[WEB]
- https://gist.github.com/GenoWang/7359360285e0fe21a7a58d10ff71d032[WEB]
- https://github.com/home-assistant/core[PACKAGE]
- https://github.com/home-assistant/core/blob/a4d12694dae82f10e2ca9c524e44a22ab7dacf66/homeassistant/components/downloader/services.py#L32[WEB]
- https://github.com/home-assistant/core/blob/a4d12694dae82f10e2ca9c524e44a22ab7dacf66/homeassistant/util/__init__.py#L20[WEB]
- https://github.com/home-assistant/core/blob/a4d12694dae82f10e2ca9c524e44a22ab7dacf66/homeassistant/util/__init__.py#L32-L38[WEB]
- https://pypi.org/project/homeassistant[PACKAGE]
- https://github.com/advisories/GHSA-pp3g-xmm4-5cw9[ADVISORY]