PT-2026-44460 · Home Assistant · Meshcore-Card

Mxsasha

·

Published

2026-05-28

·

Updated

2026-06-03

·

CVE-2026-45323

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions MeshCore Card versions prior to 0.3.3
Description MeshCore Card provides a Lovelace card for Home Assistant. Node names are rendered without HTML escaping in the meshcore-card, which allows any node within direct or indirect radio range to execute arbitrary JavaScript in the Home Assistant frontend of users viewing the card. This is a Cross-Site Scripting (XSS) issue, where malicious scripts are injected into web pages viewed by other users.
Recommendations Update to version 0.3.3.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-45323

Affected Products

Meshcore-Card