GHSA-cqg8-v99m-gv9mHighCVSS 7.5
Home Assistant Community Store (HACS) 1.10.0 contains a path traversal vulnerability that allows...
🔗 CVE IDs covered (1)
📋 Description
Home Assistant Community Store (HACS) 1.10.0 contains a path traversal vulnerability that allows unauthenticated attackers to read sensitive files by traversing directories via the /hacsfiles/ endpoint. Attackers can retrieve the .storage/auth file containing user credentials and refresh tokens, then craft valid JWT tokens to gain administrative access to Home Assistant instances.
🔗 References (6)
- https://nvd.nist.gov/vuln/detail/CVE-2021-47942
- https://github.com/hacs/integration
- https://www.exploit-db.com/exploits/49495
- https://www.home-assistant.io
- https://www.vulncheck.com/advisories/home-assistant-community-store-path-traversal-account-takeover
- https://github.com/advisories/GHSA-cqg8-v99m-gv9m