{"id":"CVE-2026-45323","summary":"MeshCore Card: XSS vulnerability through meshcore node name","details":"MeshCore Card provides MeshCore Lovelace card for Home Assistant. Prior to 0.3.3, Meshcore node names are rendered without HTML escaping in meshcore-card, allowing any node within direct or indirect (repeated) radio range to execute arbitrary javascript in the Home Assistant frontend of anyone viewing the card. This vulnerability is fixed in 0.3.3.","aliases":["GHSA-5vrg-xpcj-xppc"],"modified":"2026-07-15T01:49:16.547808067Z","published":"2026-05-28T16:54:32.847Z","database_specific":{"cwe_ids":["CWE-79"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/45xxx/CVE-2026-45323.json","cna_assigner":"GitHub_M"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/45xxx/CVE-2026-45323.json"},{"type":"ADVISORY","url":"https://github.com/jpettitt/meshcore-card/security/advisories/GHSA-5vrg-xpcj-xppc"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-45323"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/jpettitt/meshcore-card","events":[{"introduced":"0"},{"fixed":"23d01e4165dfbf92e31ed65e1a17d40314e2a1fc"}],"database_specific":{"cpe":"cpe:2.3:a:jpettitt:meshcore_card:*:*:*:*:*:home_assistant:*:*","extracted_events":[{"introduced":"0"},{"fixed":"0.3.3"}],"source":["AFFECTED_FIELD","CPE_RANGE"]}}],"versions":["v0.3.2","v0.3.1","v0.2.0","v0.1.0","v1.0.0","v0.0.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-45323.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"}]}