CVE-2021-47942

Home Assistant Community Store (HACS) prior to 1.10.0 contains a path traversal vulnerability that allows unauthenticated attackers to read sensitive files by traversing directories via the /hacsfiles/ endpoint. Attackers can retrieve the .storage/auth file containing user credentials and refresh tokens, then craft valid JWT tokens to gain administrative access to Home Assistant instances.
Configurations

Configuration 1 (hide)

cpe:2.3:a:hacs:home_assistant_community_store:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-05-16 16:16

Updated : 2026-06-17 04:18


NVD link : CVE-2021-47942

Mitre link : CVE-2021-47942

CVE.ORG link : CVE-2021-47942


JSON object : View

Products Affected

hacs

  • home_assistant_community_store
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')