CVE-2026-33044: 
Python vulnerability analysis and mitigation

Overview

CVE-2026-33044 is a stored Cross-Site Scripting (XSS) vulnerability in Home Assistant's Map-card component that allows an authenticated attacker to inject malicious JavaScript via a crafted device entity name. Affecting versions 2020.02 through 2026.01 (exclusive), the flaw is triggered when a victim hovers over a data point on a Map-card configured with the hours_to_show attribute. It was published on March 27, 2026, and fixed in version 2026.01. The vulnerability carries a CVSS v3.1 score of 5.4 (Medium) and a CVSS v4.0 score of 7.3 (High) per Feedly threat intelligence, though the GitHub Advisory Database rates it Low (1.1) under a more conservative CVSS v4 assessment (GitHub Advisory, HA Security Advisory).

Technical details

The root cause is improper neutralization of user-controlled input in the Map-card rendering logic, classified as CWE-79 (Cross-site Scripting) and CWE-80 (Improper Neutralization of Script-Related HTML Tags). An authenticated user registers or renames a location-providing device entity with a malicious name containing HTML/JavaScript payloads (e.g., test <img src=x onerror=alert(document.domain) />) and adds it to a Map-card with the hours_to_show attribute set to display movement history. The payload is stored server-side and executes in the victim's browser context when they hover over a movement trail data point on the dashboard. This vulnerability closely resembles CVE-2025-62172, which affected the energy dashboard component via a similar stored XSS mechanism (HA Security Advisory, GitHub Advisory).

Impact

Successful exploitation allows an authenticated attacker to execute arbitrary JavaScript in the browser context of any other user who views the affected dashboard, enabling session cookie theft, account takeover, unauthorized actions on behalf of the victim, and redirection to malicious sites. The attack scope extends to all users with access to dashboards containing the malicious Map-card, including administrators. While availability is not directly impacted, the confidentiality and integrity of affected user sessions are at risk; cloud-connected devices could theoretically allow a remote threat actor to deliver the payload without direct system access (HA Security Advisory, GitHub Advisory).

Exploitability

A proof-of-concept (PoC) with detailed step-by-step reproduction steps and concrete payloads is publicly available in the GitHub Security Advisory (HA Security Advisory). The CVSS v4.0 exploit maturity is rated "Proof of Concept" (E:P). The EPSS score is approximately 0.047% (0.021% per GitHub Advisory), indicating a low but non-zero probability of exploitation in the wild. There is no current evidence of active in-the-wild exploitation or threat actor attribution, and the vulnerability is not listed in the CISA KEV catalog (GitHub Advisory).

Exploitation steps

  1. Gain authenticated access: Log in to the target Home Assistant instance with any authenticated user account that has permission to register or rename device entities.
  2. Create or rename a malicious entity: Register a new location-providing sensor/device or rename an existing one with a malicious name containing an XSS payload, for example: test <img src=x onerror=alert(document.domain) /> or Pixel 9 <s> Fold Robin {{7*7}}.
  3. Add entity to a Map-card: Navigate to a dashboard and add (or ensure the malicious entity is already present on) a Map-card. Configure the card with the hours_to_show attribute set to a non-zero value to enable movement history trail display.
  4. Wait for victim interaction: When another user (the victim) views the dashboard containing the Map-card and hovers over a data point (dot or line) representing the malicious entity's movement trail, the injected JavaScript payload executes in their browser context.
  5. Achieve objective: The executed script can steal session cookies, exfiltrate tokens, perform actions on behalf of the victim, or redirect them to an attacker-controlled site (HA Security Advisory, GitHub Advisory).

Indicators of compromise

  • Logs: Home Assistant logs showing creation or renaming of device entities with names containing HTML special characters (<, >, ", ') or JavaScript keywords (onerror, onmouseover, alert, script).
  • File System / Configuration: Dashboard YAML or JSON configuration files containing Map-card entries with hours_to_show set and entity names containing HTML/JS syntax.
  • Network: Outbound requests from victim browsers to unexpected external domains shortly after viewing a Home Assistant dashboard (indicative of XSS-triggered data exfiltration or redirect).
  • Application State: Device or entity registry entries with anomalous names containing encoded or raw HTML tags, particularly for location-providing entities (HA Security Advisory).

Mitigation and workarounds

Upgrade Home Assistant to version 2026.01 or later, which contains the fix for this vulnerability (HA Security Advisory). As a workaround prior to patching, restrict permissions for modifying device entity names to trusted users only, and audit existing entity names for suspicious HTML or JavaScript content. Additionally, avoid configuring Map-cards with the hours_to_show attribute until the patch is applied, as this attribute is required to trigger the vulnerability (GitHub Advisory).

Community reactions

The vulnerability was discovered and reported by security researcher Robin Lunde (pwnpanda) and published by Home Assistant maintainer bramkragten on March 27, 2026 (HA Security Advisory). The advisory notes that the real-world impact is considered lower than the CVSS score suggests due to the specific configuration requirements (Map-card with hours_to_show set). Community coverage appeared on dev.to and CVE reporting aggregators shortly after disclosure (dev.to).

Additional resources


Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management