Home Assistant Blueprint Studio是Home Assistant组织的一个文件编辑器。 Home Assistant Blueprint Studio 2.5.2之前版本存在路径遍历漏洞,该漏洞源于传统无状态终端命令执行路径对cwd工作目录参数验证不严,仅检查目录是否存在而未要求其保持在Home Assistant配置目录内,可能导致管理员访问或修改配置目录之外的主机路径。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| ha-china | blueprint-studio | < 2.5.2 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| ha-china | blueprint-studio | < 2.5.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-53453 | 8.7 HIGH | Blueprint Studio API authorization bypass for non-admin Home Assistant users |
| CVE-2026-53455 | 8.6 HIGH | Blueprint Studio Git credential helper command injection |
| CVE-2026-53454 | 6.9 MEDIUM | Blueprint Studio stored Git credentials in plaintext Git credential store |
| CVE-2026-53456 | 5.6 MEDIUM | Blueprint Studio terminal SSH private key written to disk |
| CVE-2026-53458 | 5.3 MEDIUM | Blueprint Studio API exposed internal exception details |
No comments yet