Two stored cross-site scripting (XSS) vulnerabilities, CVE-2026-33044 in the Map card and CVE-2026-33045 in the History-Graph card, were disclosed in Home Assistant. The flaws allow an attacker with low privileges to inject JavaScript that executes in an authenticated victim’s browser session when the affected dashboard content is viewed. Because the code runs with the victim’s permissions, attackers can steal session tokens, access browser local storage, and abuse authenticated REST API or WebSocket connections.
The impact can escalate from session hijacking to full administrative compromise when the victim has elevated privileges. Reported abuse paths include generating long-lived access tokens, creating new administrator accounts, changing passwords, altering system configurations, and disabling security integrations. The compromise may also extend beyond the application itself, potentially giving attackers control over connected smart home devices, alarm systems, and in some deployments the underlying host, with CVE-2026-33045 rated CVSS v4.0 7.3 and both issues described as high impact despite requiring user interaction.

See affected versions and whether adversaries are exploiting it.
1 event from the most recent confirmed update back to the earliest known activity.
Two stored cross-site scripting vulnerabilities affecting Home Assistant components were publicly documented: one in the Map card and one in the History-Graph card. The disclosures describe how injected JavaScript could execute in an authenticated user's browser and enable session hijacking, token theft, and potentially administrative compromise.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
cvereports.com
Open sourcecvereports.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.