PT-2026-28466 · Unknown · Home Assistant
Pwnpanda
·
Published
2026-03-27
·
Updated
2026-03-29
·
CVE-2026-33044
CVSS v4.0
8.8
High
| Vector | AV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H |
Name of the Vulnerable Software and Affected Versions
Home Assistant versions 2020.02 through 2026.01
Description
Home Assistant, an open-source home automation software, contains a flaw where an authenticated user can inject malicious code into a device entity name. This allows for Cross-Site Scripting (XSS) attacks against other users who view a dashboard containing a Map-card that includes the compromised entity. The attack requires the victim to hover over an information point on the map. The issue is similar to a previously documented issue but affects entities displayed in a Map, rather than an energy dashboard. The impact of this flaw allows a user to potentially target other users and perform account takeover through client-side exploitation.
Recommendations
Update to version 2026.01 or later.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Home Assistant