Security Advisory

CVE-2026-45323

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-05-28 16:54:32
Last updated 2026-05-29 15:30:28
Assigner GitHub_M
CVSS score 9.6
State PUBLISHED

Description

MeshCore Card provides MeshCore Lovelace card for Home Assistant. Prior to 0.3.3, Meshcore node names are rendered without HTML escaping in meshcore-card, allowing any node within direct or indirect (repeated) radio range to execute arbitrary javascript in the Home Assistant frontend of anyone viewing the card. This vulnerability is fixed in 0.3.3.