<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T17:31:41.752048+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-33044</id>
    <title>CVE-2026-33044 — Home Assistant has stored XSS in Map-card through malicious device name</title>
    <updated>2026-10-02T17:31:41.784106+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> home-assistant core</p>
<p>Home Assistant is open source home automation software that puts local control and privacy first. Starting in version 2020.02 and prior to version 2026.01, an authenticated party can add a malicious name to their device entity, allowing for Cross-Site Scripting attacks against anyone who can see a dashboard with a Map-card which includes that entity. It requires that the victim hovers over an information point. Version 2026.01 fixes the issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-33044"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-r584-6283-p7xc</id>
    <title>GHSA-r584-6283-p7xc — Home Assistant has stored XSS in Map-card through malicious device name</title>
    <updated>2026-10-02T17:31:41.784174+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: homeassistant</p>
<p>### Summary
An authenticated party can add a malicious name to their device entity, allowing for Cross-Site Scripting attacks against anyone who can see a dashboard with a Map-card which includes that entity. It requires that the victim hovers over an information point (The lines or the dots representing that device's movement, as shown in the screenshot below, with the example showing a html-injection using `&lt;s&gt;` to strikethrough the text)
&lt;img width="348" height="355" alt="image" src="https://github.com/user-attachments/assets/1af3ef33-3a72-4816-8ade-e6405aace176" /&gt;</p>
<p>This allows an authenticated user to execute JavaScript in the context of any other users accessing a dashboard.</p>
<p>### Details</p>
<p>The vulnerability exists in the map-card by adding a malicious entity and having the property `hours_to_show` set.
See example below, with the malicious entity being `Pixel 9 &lt;s&gt; Fold Robin {{7*7}}`:
Map card with malicious device entity:
&lt;img width="338" height="332" alt="image" src="https://github.com/user-attachments/assets/15229cc3-1b69-438c-9ee5-cbfa9483aec9" /&gt;</p>
<p>YAML-view of same card:
&lt;img width="338" height="198" alt="image" src="https://github.com/user-attachments/assets/cd579266-75c3-4cdf-9d08-1544a6887feb" /&gt;</p>
<p>This issue largely resembles the issue documented in: [CVE-2025-62172](https://github.com/home-assistant/core/security/advisories/GHSA-mq77-rv97-285m), but with an entity which can be displayed in a Map, instead of in an energy-dashboard.</p>
<p>### PoC
1. Register a new…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-r584-6283-p7xc"/>
  </entry>
</feed>
