Home Assistant Blueprint Studio是Home Assistant组织的一个文件编辑器。 Home Assistant Blueprint Studio 2.5.2之前版本存在信任管理问题漏洞,该漏洞源于custom_components/blueprint_studio/backend/terminal_manager.py中SSH密钥认证在应用限制权限前将私钥写入文件,且依赖尽力清理,可能导致私钥残留,具有文件系统访问权限的用户或进程能够获取残留私钥。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| ha-china | blueprint-studio | < 2.5.2 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| ha-china | blueprint-studio | < 2.5.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-53453 | 8.7 HIGH | Blueprint Studio API authorization bypass for non-admin Home Assistant users |
| CVE-2026-53455 | 8.6 HIGH | Blueprint Studio Git credential helper command injection |
| CVE-2026-53454 | 6.9 MEDIUM | Blueprint Studio stored Git credentials in plaintext Git credential store |
| CVE-2026-53458 | 5.3 MEDIUM | Blueprint Studio API exposed internal exception details |
| CVE-2026-53457 | 5.1 MEDIUM | Blueprint Studio terminal command working directory not bounded to config directory |
No comments yet