{"id":"CVE-2026-33045","aliases":["GHSA-46j8-vpx8-6p72","PYSEC-2026-2516"],"url":"https://o3.security/vulnerability/CVE-2026-33045","summary":"Home Assistant has stored XSS in history-graphs","details":"Home Assistant is open source home automation software that puts local control and privacy first. Starting in version 2025.02 and prior to version 2026.01 the \"remaining charge time\"-sensor for mobile phones (imported/included from Android Auto it appears) is vulnerable cross-site scripting, similar to CVE-2025-62172. Version 2026.01 fixes the issue.","published":"2026-03-27T19:39:03.590Z","modified":"2026-08-07T11:31:35.556475075Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"homeassistant","fixedVersion":"2026.01"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/33xxx/CVE-2026-33045.json"},{"type":"ADVISORY","url":"https://github.com/home-assistant/core/security/advisories/GHSA-46j8-vpx8-6p72"},{"type":"ADVISORY","url":"https://github.com/home-assistant/core/security/advisories/GHSA-mq77-rv97-285m"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-33045"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T11:31:35.556475075Z"}}