rising3월 29일· 2 sources

Home Assistant Map-Card Flaw Enables Account Hijacking Through JavaScript Injection

Home Assistant Map-Card의 저장된 XSS 취약점, 계정 탈취 위험

Why it matters

CVE-2026-33044 reveals a critical stored XSS vulnerability in Home Assistant's Map-Card component that allows authenticated attackers to execute arbitrary JavaScript in victim browsers. This flaw, rated CVSS 7.3, enables account takeover and session hijacking, with active proof-of-concept exploits already available. Immediate upgrade to version 2026.01 is essential for all affected Home Assistant users.

2
Sources
+0
24h
Growth
169d
Active
Session hijackingHistory-graph cardCVE-2026-33044Stored XSSAccount takeoverMap-CardAccount Takeover

Sources

Related Issues