CVE-2026-33045: 
Python vulnerability analysis and mitigation

Overview

CVE-2026-33045 is a stored Cross-Site Scripting (XSS) vulnerability in Home Assistant's history-graph card, specifically affecting the "remaining charge time" sensor for mobile phones imported via Android Auto. The vulnerability is similar to CVE-2025-62172 and likely affects any sensor whose name is rendered in the history-graph card without proper sanitization. It affects Home Assistant versions 2025.02 through 2026.00, with version 2026.01 containing the fix. The vulnerability was disclosed on March 27, 2026, and carries a CVSS v3.1 score of 5.4 (Medium) and a CVSS v4.0 score of 7.3 (High) (Github Advisory, HA Advisory).

Technical details

The root cause is improper neutralization of script-related HTML tags in a web page (CWE-79/CWE-80): the Home Assistant frontend renders entity names directly into history-graph card tooltips without output escaping or sanitization. An authenticated attacker with low privileges can set a malicious entity name (e.g., test <img src=x onerror=alert(document.domain) />) on the "remaining charge time" sensor or any sensor displayed in a history-graph card. The payload executes when another user hovers over the graph, making this a stored XSS triggered by user interaction. The vulnerability requires the attacker to have write access to entity names and a victim to view and interact with the affected history-graph card (HA Advisory, Github Advisory).

Impact

Successful exploitation allows an attacker to execute arbitrary JavaScript in the browser context of other Home Assistant users, enabling session token theft, forged requests, and account takeover. The vulnerability's scope is somewhat limited in practice because the history-graph card is not displayed by default and requires deliberate configuration, and exploitation currently appears to rely on Android Auto usage or similar integrations. However, the advisory notes that cloud-connected devices could theoretically allow a remote threat actor to deliver the payload without direct access to the Home Assistant instance (HA Advisory).

Exploitability

Proof-of-concept exploit steps are publicly available in the GitHub security advisory, including a concrete payload (test <img src=x onerror=alert(document.domain) />) and sequential reproduction steps. The CVSS v4.0 exploit maturity is rated "Proof of Concept" (E:P). There is no evidence of in-the-wild exploitation at this time, and no threat actor attribution has been reported. The EPSS score is approximately 0.047% (0.000470), placing it in a low exploitation probability tier (Github Advisory, HA Advisory).

Exploitation steps

  1. Gain low-privileged access: Obtain an authenticated account on the target Home Assistant instance with permission to rename entities or sensors.
  2. Identify or register a target sensor: Locate the "remaining charge time" sensor (from Android Auto) or any other sensor that can be displayed in a history-graph card.
  3. Inject malicious payload into entity name: Rename the sensor to a malicious value, for example: test <img src=x onerror=alert(document.domain) />.
  4. Configure a history-graph card: Add a history-graph card to a Home Assistant dashboard that includes the maliciously named sensor.
  5. Wait for victim interaction: When another authenticated user views the dashboard and hovers over the history-graph card displaying the sensor, the injected JavaScript executes in their browser context.
  6. Achieve objective: Use the XSS to steal session tokens, perform actions on behalf of the victim, or escalate to account takeover (HA Advisory, Github Advisory).

Indicators of compromise

  • Logs: Home Assistant audit logs showing unexpected entity name changes, particularly for the "remaining charge time" sensor or other sensors, to values containing HTML tags (e.g., <img, <script, onerror=, alert().
  • Network: Outbound HTTP requests from a victim's browser to attacker-controlled infrastructure (e.g., for cookie/token exfiltration) originating from the Home Assistant web interface domain.
  • Application: Presence of HTML or JavaScript payloads in entity friendly names stored in the Home Assistant configuration or database (e.g., <img src=x onerror=...>, <script>, or encoded variants).
  • Browser: Unexpected JavaScript execution or pop-ups when hovering over history-graph cards in the Home Assistant Lovelace dashboard.

Mitigation and workarounds

Upgrade Home Assistant to version 2026.01 or later, which contains the fix for this vulnerability (Github Advisory). Until patching is possible, restrict access to the Home Assistant web interface to trusted users only, and avoid adding history-graph cards that display sensor names from untrusted sources. Disabling or removing the Android Auto integration if it is not in use will also reduce the attack surface. Audit existing entity names for suspicious HTML or JavaScript content as an additional precaution.

Community reactions

The vulnerability was reported by security researcher Robin Lunde (pwnpanda) and published by Home Assistant maintainer bramkragten on March 27, 2026. The reporter noted that the vulnerability is less impactful in practice than the CVSS score suggests, as the history-graph card is not displayed by default and requires deliberate configuration. No significant broader media coverage or notable community debate has been identified beyond the official advisory (HA Advisory).

Additional resources


Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management