目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CVE-2026-53454— Blueprint Studio Git凭证明文存储漏洞

CVSS 6.9 · Medium
获取后续新漏洞提醒登录后订阅

一、 漏洞 CVE-2026-53454 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
Blueprint Studio stored Git credentials in plaintext Git credential store
来源: CVE Program / CVE List V5
Vulnerability Description
Blueprint Studio is a VS Code-like file editor for Home Assistant configuration files. Prior to 2.5.2, Blueprint Studio configured Git's credential.helper store when saving Git credentials, causing Git credential-store to persist usernames and access tokens in plaintext in the .git-credentials file for the user running Home Assistant. Tokens could remain outside Blueprint Studio's intended Home Assistant storage and be read by other users or processes with access to the same filesystem context. The persistent helper configuration also affected later Git operations beyond the immediate Blueprint Studio action. This issue is fixed in version 2.5.2.
来源: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
来源: CVE Program / CVE List V5
Vulnerability Type
不充分的凭证保护机制
来源: CVE Program / CVE List V5

受影响产品

厂商产品影响版本CPE订阅
ha-chinablueprint-studio < 2.5.2 -

二、漏洞 CVE-2026-53454 的公开POC

#POC 描述源链接神龙链接
AI 生成 POC高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2026-53454 的情报信息

登录查看更多情报信息。

CVE-2026-53454 补丁与修复 (2)

CVE-2026-53454 厂商安全公告 (1)

同批安全公告 · ha-china · 2026-08-18 · 共 6 条

CVE-2026-534538.7 HIGHHome Assistant Blueprint Studio API 非管理员授权绕过漏洞
CVE-2026-534558.6 HIGHBlueprint Studio Git凭据助手命令注入漏洞
CVE-2026-534565.6 MEDIUMBlueprint Studio SSH私钥泄露漏洞
CVE-2026-534585.3 MEDIUMBlueprint Studio API 暴露内部异常详情漏洞
CVE-2026-534575.1 MEDIUMBlueprint Studio 终端命令工作目录未绑定到配置目录

IV. Related Vulnerabilities

V. Comments for CVE-2026-53454

暂无评论


发表评论