Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 27 May 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Hacs
Hacs home Assistant Community Store |
|
| CPEs | cpe:2.3:a:hacs:home_assistant_community_store:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Hacs
Hacs home Assistant Community Store |
Tue, 26 May 2026 00:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Home Assistant Community Store (HACS) 1.10.0 contains a path traversal vulnerability that allows unauthenticated attackers to read sensitive files by traversing directories via the /hacsfiles/ endpoint. Attackers can retrieve the .storage/auth file containing user credentials and refresh tokens, then craft valid JWT tokens to gain administrative access to Home Assistant instances. | Home Assistant Community Store (HACS) prior to 1.10.0 contains a path traversal vulnerability that allows unauthenticated attackers to read sensitive files by traversing directories via the /hacsfiles/ endpoint. Attackers can retrieve the .storage/auth file containing user credentials and refresh tokens, then craft valid JWT tokens to gain administrative access to Home Assistant instances. |
Mon, 18 May 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sun, 17 May 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Home-assistant
Home-assistant home Assistant Community Store |
|
| Vendors & Products |
Home-assistant
Home-assistant home Assistant Community Store |
Sat, 16 May 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Home Assistant Community Store (HACS) 1.10.0 contains a path traversal vulnerability that allows unauthenticated attackers to read sensitive files by traversing directories via the /hacsfiles/ endpoint. Attackers can retrieve the .storage/auth file containing user credentials and refresh tokens, then craft valid JWT tokens to gain administrative access to Home Assistant instances. | |
| Title | Home Assistant Community Store 1.10.0 Path Traversal Account Takeover | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-05-25T23:41:16.426Z
Reserved: 2026-02-01T11:24:18.718Z
Link: CVE-2021-47942
Updated: 2026-05-18T19:58:54.430Z
Status : Analyzed
Published: 2026-05-16T16:16:21.390
Modified: 2026-06-17T04:18:48.067
Link: CVE-2021-47942
No data.
OpenCVE Enrichment
Updated: 2026-05-26T02:30:26Z