S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Apr 23, 2026

CVE-2021-3152 Scanner

CVE-2021-3152 Scanner - Local File Inclusion (LFI) vulnerability in Home Assistant HACS

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
3k
Times Used
continuous scan runs
3.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-3152
5.3
CVSS

Home Assistant before 2021.1.3 does not have a protection layer that can help to prevent directory-traversal attacks against custom integrations. NOTE: the vendor's perspective is that the vulnerability itself is in custom integrations written by third parties, not in Home Assistant; however, Home Assistant does have a security update that is worthwhile in addressing this situation

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

Home Assistant HACS (Home Assistant Community Store) is widely used by home automation enthusiasts to manage and install custom integrations. It serves as a repository for various third-party plugins that extend the functionality of Home Assistant, an open-source platform for smart home devices. Developers and users alike leverage HACS to automate and enhance their home systems with custom scripts and integrations. However, the flexibility of custom integrations presents inherent security risks when insufficiently managed. Maintaining up-to-date security patches is crucial to ensure that home networks remain secure from external threats. Home Assistant's community and the platform's open-source nature contribute to its continuous evolution and improvement in addressing security concerns.

The Local File Inclusion (LFI) vulnerability identified in Home Assistant HACS allows attackers to exploit directory traversal flaws. This type of vulnerability occurs when input data is improperly sanitized, allowing attackers to access arbitrary files on the server. Such vulnerabilities can have serious consequences as they enable unauthorized file access, leading to information disclosure. The exploitation of LFI vulnerabilities doesn't typically require high technical expertise, making it more accessible to potential attackers. Home Assistant versions prior to 2021.1.3 are susceptible to this vulnerability due to inadequate protections in handling custom integrations. Addressing this vulnerability is critical to protecting the confidentiality and integrity of sensitive data.

Technical details about the Local File Inclusion vulnerability in Home Assistant HACS reveal specific exploitation pathways. Attackers can deploy a malicious custom integration to perform directory traversal attacks and access files like `configuration.yaml`. The vulnerable parameter involves paths that utilize relative directory terms, typically executed through HTTP GET requests. Successful exploitation is contingent on the presence of specific markers within the response body, such as 'default_config:' or 'homeassistant:'. A status code of 200 indicates successful file access, further exposing system files. The exploitable endpoint is tied to the `/hacsfiles/` path, highlighting the need for a secure configuration to safeguard against such attacks.

When exploited, the Local File Inclusion vulnerability can have several severe effects. Unauthorized access to sensitive configuration files may lead to the disclosure of critical information, such as API keys or device settings, compromising the security posture of the home system. Compromised files may facilitate further attacks, enabling attackers to escalate privileges or launch targeted assaults on the network. The impact of such data breaches can result in significant privacy violations and unauthorized control over home automation devices. Remediation involves updating the Home Assistant to version 2021.1.3 or later, applying patches that mitigate the directory traversal risk in custom integrations.

REFERENCES

Solution Advice
  • Update Home Assistant to version 2021.1.3 or later to incorporate necessary security patches.
  • Review and validate the security of any custom integrations before deployment.
  • Regularly audit server configurations to ensure that directory traversal attacks are mitigated.
  • Implement strict input validation techniques to prevent arbitrary file access.
  • Monitor system logs for unauthorized access attempts and file access patterns.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.