Medium severity5.4NVD Advisory· Published Mar 27, 2026· Updated Mar 31, 2026
CVE-2026-33045
CVE-2026-33045
Description
Home Assistant is open source home automation software that puts local control and privacy first. Starting in version 2025.02 and prior to version 2026.01 the "remaining charge time"-sensor for mobile phones (imported/included from Android Auto it appears) is vulnerable cross-site scripting, similar to CVE-2025-62172. Version 2026.01 fixes the issue.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
homeassistantPyPI | >= 2025.02, < 2026.01 | 2026.01 |
Affected products
1- cpe:2.3:a:home-assistant:home-assistant:*:*:*:*:*:*:*:*Range: >=2025.2.0,<2026.1.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- github.com/home-assistant/core/security/advisories/GHSA-46j8-vpx8-6p72nvdExploitVendor AdvisoryWEB
- github.com/home-assistant/core/security/advisories/GHSA-mq77-rv97-285mnvdExploitVendor AdvisoryWEB
- github.com/advisories/GHSA-46j8-vpx8-6p72ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-33045ghsaADVISORY
News mentions
0No linked articles in our index yet.