{"id":"CVE-2026-33044","aliases":["GHSA-r584-6283-p7xc","PYSEC-2026-2517"],"url":"https://o3.security/vulnerability/CVE-2026-33044","summary":"Home Assistant has stored XSS in Map-card through malicious device name","details":"Home Assistant is open source home automation software that puts local control and privacy first. Starting in version 2020.02 and prior to version 2026.01, an authenticated party can add a malicious name to their device entity, allowing for Cross-Site Scripting attacks against anyone who can see a dashboard with a Map-card which includes that entity. It requires that the victim hovers over an information point. Version 2026.01 fixes the issue.","published":"2026-03-27T19:35:45.728Z","modified":"2026-08-07T11:31:10.662155542Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"homeassistant","fixedVersion":"2026.01"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/33xxx/CVE-2026-33044.json"},{"type":"ADVISORY","url":"https://github.com/home-assistant/core/security/advisories/GHSA-r584-6283-p7xc"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-33044"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T11:31:10.662155542Z"}}