CVE-2026-64824 | home-assistant Home Assistant Core up to 2026.5.x sitecustomize.py backup-restore linkname path traversal

SecurityVulns

A vulnerability was found in home-assistant Home Assistant Core up to 2026.5.x and classified as very critical. Affected by this issue is the function backup-restore of the file site-packages/sitecustomize.py. Executing a manipulation of the argument linkname can lead to path traversal.

This vulnerability is handled as CVE-2026-64824. The attack can be executed remotely. There is not any exploit available.VulDB Recent EntriesRead More