
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-33044 is a stored Cross-Site Scripting (XSS) vulnerability in Home Assistant's Map-card component that allows an authenticated attacker to inject malicious JavaScript via a crafted device entity name. Affecting versions 2020.02 through 2026.01 (exclusive), the flaw is triggered when a victim hovers over a data point on a Map-card configured with the hours_to_show attribute. It was published on March 27, 2026, and fixed in version 2026.01. The vulnerability carries a CVSS v3.1 score of 5.4 (Medium) and a CVSS v4.0 score of 7.3 (High) per Feedly threat intelligence, though the GitHub Advisory Database rates it Low (1.1) under a more conservative CVSS v4 assessment (GitHub Advisory, HA Security Advisory).
The root cause is improper neutralization of user-controlled input in the Map-card rendering logic, classified as CWE-79 (Cross-site Scripting) and CWE-80 (Improper Neutralization of Script-Related HTML Tags). An authenticated user registers or renames a location-providing device entity with a malicious name containing HTML/JavaScript payloads (e.g., test <img src=x onerror=alert(document.domain) />) and adds it to a Map-card with the hours_to_show attribute set to display movement history. The payload is stored server-side and executes in the victim's browser context when they hover over a movement trail data point on the dashboard. This vulnerability closely resembles CVE-2025-62172, which affected the energy dashboard component via a similar stored XSS mechanism (HA Security Advisory, GitHub Advisory).
Successful exploitation allows an authenticated attacker to execute arbitrary JavaScript in the browser context of any other user who views the affected dashboard, enabling session cookie theft, account takeover, unauthorized actions on behalf of the victim, and redirection to malicious sites. The attack scope extends to all users with access to dashboards containing the malicious Map-card, including administrators. While availability is not directly impacted, the confidentiality and integrity of affected user sessions are at risk; cloud-connected devices could theoretically allow a remote threat actor to deliver the payload without direct system access (HA Security Advisory, GitHub Advisory).
A proof-of-concept (PoC) with detailed step-by-step reproduction steps and concrete payloads is publicly available in the GitHub Security Advisory (HA Security Advisory). The CVSS v4.0 exploit maturity is rated "Proof of Concept" (E:P). The EPSS score is approximately 0.047% (0.021% per GitHub Advisory), indicating a low but non-zero probability of exploitation in the wild. There is no current evidence of active in-the-wild exploitation or threat actor attribution, and the vulnerability is not listed in the CISA KEV catalog (GitHub Advisory).
test <img src=x onerror=alert(document.domain) /> or Pixel 9 <s> Fold Robin {{7*7}}.hours_to_show attribute set to a non-zero value to enable movement history trail display.<, >, ", ') or JavaScript keywords (onerror, onmouseover, alert, script).hours_to_show set and entity names containing HTML/JS syntax.Upgrade Home Assistant to version 2026.01 or later, which contains the fix for this vulnerability (HA Security Advisory). As a workaround prior to patching, restrict permissions for modifying device entity names to trusted users only, and audit existing entity names for suspicious HTML or JavaScript content. Additionally, avoid configuring Map-cards with the hours_to_show attribute until the patch is applied, as this attribute is required to trigger the vulnerability (GitHub Advisory).
The vulnerability was discovered and reported by security researcher Robin Lunde (pwnpanda) and published by Home Assistant maintainer bramkragten on March 27, 2026 (HA Security Advisory). The advisory notes that the real-world impact is considered lower than the CVSS score suggests due to the specific configuration requirements (Map-card with hours_to_show set). Community coverage appeared on dev.to and CVE reporting aggregators shortly after disclosure (dev.to).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."