CVE-2026-33044

Home Assistant is open source home automation software that puts local control and privacy first. Starting in version 2020.02 and prior to version 2026.01, an authenticated party can add a malicious name to their device entity, allowing for Cross-Site Scripting attacks against anyone who can see a dashboard with a Map-card which includes that entity. It requires that the victim hovers over an information point. Version 2026.01 fixes the issue.
Configurations

Configuration 1 (hide)

cpe:2.3:a:home-assistant:home-assistant:*:*:*:*:*:*:*:*

History

31 Mar 2026, 14:09

Type Values Removed Values Added
CPE cpe:2.3:a:home-assistant:home-assistant:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.4
First Time Home-assistant home-assistant
Home-assistant
References () https://github.com/home-assistant/core/security/advisories/GHSA-r584-6283-p7xc - () https://github.com/home-assistant/core/security/advisories/GHSA-r584-6283-p7xc - Exploit, Vendor Advisory

27 Mar 2026, 20:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-27 20:16

Updated : 2026-03-31 15:42


NVD link : CVE-2026-33044

Mitre link : CVE-2026-33044

CVE.ORG link : CVE-2026-33044


JSON object : View

Products Affected

home-assistant

  • home-assistant
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')