Home Assistant is open source home automation software that puts local control and privacy first. Starting in version 2025.02 and prior to version 2026.01 the "remaining charge time"-sensor for mobile phones (imported/included from Android Auto it appears) is vulnerable cross-site scripting, similar to CVE-2025-62172. Version 2026.01 fixes the issue.
{
"cna_assigner": "GitHub_M",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/33xxx/CVE-2026-33045.json",
"unresolved_ranges": [
{
"extracted_events": [
{
"introduced": "2025.02"
},
{
"fixed": "2026.01"
}
],
"source": "AFFECTED_FIELD"
}
],
"cwe_ids": [
"CWE-79"
]
}