CVE-2026-33044 | home-assistant core prior 2026.01 cross site scripting (GHSA-r584-6283-p7xc / EUVD-2026-16774)
A vulnerability was found in home-assistant core. It has been declared as problematic. The affected element is an unknown function. Executing a manipulation can lead to cross site scripting.
This vulnerability is tracked as CVE-2026-33044. The attack can be launched remotely. No exploit exists.
It is recommended to upgrade the affected component.