VYPR
Medium severity4.0OSV Advisory· Published Dec 23, 2025· Updated Jun 17, 2026

CVE-2025-65713

CVE-2025-65713

Description

Home Assistant Core before v2025.8.0 is vulnerable to Directory Traversal. The Downloader integration does not fully validate file paths during concatenation, leaving a path traversal vulnerability.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
homeassistantPyPI
< 2025.8.02025.8.0

Affected products

3
  • 0.103.0, 0.103.0b0, 0.103.0b1, …+ 1 more
    • (no CPE)range: 0.103.0, 0.103.0b0, 0.103.0b1, …
    • cpe:2.3:a:home-assistant:home-assistant:*:*:*:*:*:*:*:*range: <2025.8.0
  • ghsa-coords
    Range: < 2025.8.0

Patches

Vulnerability mechanics

References

7

News mentions

0

No linked articles in our index yet.