Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-r584-6283-p7xc | Home Assistant has stored XSS in Map-card through malicious device name |
Thu, 02 Apr 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
ssvc
|
Tue, 31 Mar 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 31 Mar 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Home-assistant home-assistant
|
|
| CPEs | cpe:2.3:a:home-assistant:home-assistant:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Home-assistant home-assistant
|
|
| Metrics |
cvssV3_1
|
Mon, 30 Mar 2026 07:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Home-assistant
Home-assistant core |
|
| Vendors & Products |
Home-assistant
Home-assistant core |
Fri, 27 Mar 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Home Assistant is open source home automation software that puts local control and privacy first. Starting in version 2020.02 and prior to version 2026.01, an authenticated party can add a malicious name to their device entity, allowing for Cross-Site Scripting attacks against anyone who can see a dashboard with a Map-card which includes that entity. It requires that the victim hovers over an information point. Version 2026.01 fixes the issue. | |
| Title | Home Assistant has stored XSS in Map-card through malicious device name | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-04-02T13:08:11.661Z
Reserved: 2026-03-17T18:10:50.211Z
Link: CVE-2026-33044
Updated: 2026-03-31T13:50:55.726Z
Status : Analyzed
Published: 2026-03-27T20:16:30.980
Modified: 2026-03-31T15:42:30.977
Link: CVE-2026-33044
No data.
OpenCVE Enrichment
Updated: 2026-03-31T20:00:48Z
Github GHSA