{"id":"CVE-2025-65713","aliases":["GHSA-pp3g-xmm4-5cw9","PYSEC-2026-1454"],"url":"https://o3.security/vulnerability/CVE-2025-65713","summary":"Home Assistant Core before is vulnerable to Directory Traversal","details":"Home Assistant Core before v2025.8.0 is vulnerable to Directory Traversal. The Downloader integration does not fully validate file paths during concatenation, leaving a path traversal vulnerability.","published":"2025-12-23T00:00:00Z","modified":"2026-08-08T03:48:15.885232455Z","cvss":{"score":4,"severity":"MEDIUM","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"homeassistant","fixedVersion":"2025.8.0"}],"fix":{"url":"https://github.com/home-assistant/core/pull/150046","label":"home-assistant/core#150046"},"references":[{"type":"WEB","url":"https://gist.github.com/GenoWang/7359360285e0fe21a7a58d10ff71d032"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/65xxx/CVE-2025-65713.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-65713"},{"type":"FIX","url":"https://github.com/home-assistant/core/pull/150046"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-08T03:48:15.885232455Z"}}