Beveiligingsadvies

CVE-2026-45323

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-05-28 16:54:32
Laatst bijgewerkt 2026-05-29 15:30:28
Toegewezen door GitHub_M
CVSS-score 9.6
Status PUBLISHED

Beschrijving

MeshCore Card provides MeshCore Lovelace card for Home Assistant. Prior to 0.3.3, Meshcore node names are rendered without HTML escaping in meshcore-card, allowing any node within direct or indirect (repeated) radio range to execute arbitrary javascript in the Home Assistant frontend of anyone viewing the card. This vulnerability is fixed in 0.3.3.