Cross-Site Scripting Vulnerability in Home Assistant Software
CVE-2026-33045

7.3HIGH

Key Information:

Status
Vendor
CVE Published:
27 March 2026

What is CVE-2026-33045?

Home Assistant, an open-source home automation software prioritizing local control and privacy, is susceptible to cross-site scripting vulnerabilities. Specifically, prior to version 2026.01, the 'remaining charge time'-sensor, included from Android Auto, could potentially allow attackers to inject malicious scripts. This issue, notable for its similarity to another vulnerability identified previously, was addressed in version 2026.01, which mitigates the associated risks.

Affected Version(s)

core >= 2025.02, < 2026.01

References

CVSS V4

Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.