Home Assistant is open source home automation software that puts local control and privacy first. Starting in version 2020.02 and prior to version 2026.01, an authenticated party can add a malicious name to their device entity, allowing for Cross-Site Scripting attacks against anyone who can see a dashboard with a Map-card which includes that entity. It requires that the victim hovers over an information point. Version 2026.01 fixes the issue.
Metrics
Affected Vendors & Products
References
History
Fri, 27 Mar 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Home Assistant is open source home automation software that puts local control and privacy first. Starting in version 2020.02 and prior to version 2026.01, an authenticated party can add a malicious name to their device entity, allowing for Cross-Site Scripting attacks against anyone who can see a dashboard with a Map-card which includes that entity. It requires that the victim hovers over an information point. Version 2026.01 fixes the issue. | |
| Title | Home Assistant has stored XSS in Map-card through malicious device name | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-03-27T19:35:45.728Z
Reserved: 2026-03-17T18:10:50.211Z
Link: CVE-2026-33044
No data.
Status : Received
Published: 2026-03-27T20:16:30.980
Modified: 2026-03-27T20:16:30.980
Link: CVE-2026-33044
No data.
OpenCVE Enrichment
No data.