Cross-Site Scripting Vulnerability in Home Assistant Software
CVE-2026-33044

7.3HIGH

Key Information:

Status
Vendor
CVE Published:
27 March 2026

What is CVE-2026-33044?

An issue within Home Assistant's open-source home automation software allows authenticated users to introduce malicious names into device entities. This vulnerability potentially enables Cross-Site Scripting (XSS) attacks against users who view a dashboard containing a Map-card with such an entity. Victims must hover over information points to trigger the attack, making it crucial for users to update to version 2026.01 or later, which contains fixes to mitigate this risk.

Affected Version(s)

core >= 2020.02, < 2026.01

References

CVSS V4

Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.