Beveiligingsadvies

CVE-2021-47942

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-05-16 15:28:07
Laatst bijgewerkt 2026-08-14 16:49:21
Toegewezen door VulnCheck
CVSS-score 8.7
Status PUBLISHED

Beschrijving

Home Assistant Community Store (HACS) prior to 1.10.0 contains a path traversal vulnerability that allows unauthenticated attackers to read sensitive files by traversing directories via the /hacsfiles/ endpoint. Attackers can retrieve the .storage/auth file containing user credentials and refresh tokens, then craft valid JWT tokens to gain administrative access to Home Assistant instances.