


Perceptive Security
SOC/SIEM Consultancy

MeshCore Card provides MeshCore Lovelace card for Home Assistant. Prior to 0.3.3, Meshcore node names are rendered without HTML escaping in meshcore-card, allow…
Published:
27 May 2026 at 22:00:00
Alert date:
28 May 2026 at 19:09:38
Source:
nvd.nist.gov
Mobile & IoT, Web Technologies
MeshCore Card for Home Assistant contains a cross-site scripting (XSS) vulnerability prior to version 0.3.3. The vulnerability occurs because MeshCore node names are rendered without proper HTML escaping in the meshcore-card component. This allows any node within direct or indirect radio range to execute arbitrary JavaScript code in the Home Assistant frontend when users view the card. The vulnerability has been patched in version 0.3.3 of the MeshCore Card.
Technical details
Mitigation steps:
Affected products:
MeshCore Card
Home Assistant
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-45323
https://github.com/jpettitt/meshcore-card/security/advisories/GHSA-5vrg-xpcj-xppc
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
