CVE-2021-47942

Home Assistant Community Store (HACS) prior to 1.10.0 contains a path traversal vulnerability that allows unauthenticated attackers to read sensitive files by traversing directories via the /hacsfiles/ endpoint. Attackers can retrieve the .storage/auth file containing user credentials and refresh tokens, then craft valid JWT tokens to gain administrative access to Home Assistant instances.
Configurations

Configuration 1 (hide)

cpe:2.3:a:hacs:home_assistant_community_store:*:*:*:*:*:*:*:*

History

27 May 2026, 20:42

Type Values Removed Values Added
References () https://github.com/hacs/integration - () https://github.com/hacs/integration - Product
References () https://www.exploit-db.com/exploits/49495 - () https://www.exploit-db.com/exploits/49495 - Exploit
References () https://www.home-assistant.io/ - () https://www.home-assistant.io/ - Product
References () https://www.vulncheck.com/advisories/home-assistant-community-store-path-traversal-account-takeover - () https://www.vulncheck.com/advisories/home-assistant-community-store-path-traversal-account-takeover - Third Party Advisory
CPE cpe:2.3:a:hacs:home_assistant_community_store:*:*:*:*:*:*:*:*
First Time Hacs home Assistant Community Store
Hacs

26 May 2026, 00:16

Type Values Removed Values Added
Summary (en) Home Assistant Community Store (HACS) 1.10.0 contains a path traversal vulnerability that allows unauthenticated attackers to read sensitive files by traversing directories via the /hacsfiles/ endpoint. Attackers can retrieve the .storage/auth file containing user credentials and refresh tokens, then craft valid JWT tokens to gain administrative access to Home Assistant instances. (en) Home Assistant Community Store (HACS) prior to 1.10.0 contains a path traversal vulnerability that allows unauthenticated attackers to read sensitive files by traversing directories via the /hacsfiles/ endpoint. Attackers can retrieve the .storage/auth file containing user credentials and refresh tokens, then craft valid JWT tokens to gain administrative access to Home Assistant instances.

16 May 2026, 16:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-16 16:16

Updated : 2026-05-27 20:42


NVD link : CVE-2021-47942

Mitre link : CVE-2021-47942

CVE.ORG link : CVE-2021-47942


JSON object : View

Products Affected

hacs

  • home_assistant_community_store
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')