Medium severity5.3NVD Advisory· Published Jan 26, 2021· Updated Jun 17, 2026
CVE-2021-3152
CVE-2021-3152
Description
Home Assistant before 2021.1.3 does not have a protection layer that can help to prevent directory-traversal attacks against custom integrations. NOTE: the vendor's perspective is that the vulnerability itself is in custom integrations written by third parties, not in Home Assistant; however, Home Assistant does have a security update that is worthwhile in addressing this situation
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:home-assistant:home-assistant:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:home-assistant:home-assistant:*:*:*:*:*:*:*:*range: <2021.1.3
- (no CPE)range: <2021.1.3
- Home Assistant/Home Assistantdescription
Patches
Vulnerability mechanics
References
2- www.home-assistant.io/blog/2021/01/14/security-bulletin/nvdVendor Advisory
- www.home-assistant.io/blog/2021/01/22/security-disclosure/nvdVendor Advisory
News mentions
0No linked articles in our index yet.