Home Assistant Blueprint Studio是Home Assistant组织的一个文件编辑器。 Home Assistant Blueprint Studio 2.5.2之前版本存在信息泄露漏洞,该漏洞源于后端API处理程序返回原始异常字符串,可能导致信息泄露,帮助已认证用户识别安装信息并改进后续攻击。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| ha-china | blueprint-studio | < 2.5.2 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| ha-china | blueprint-studio | < 2.5.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-53453 | 8.7 HIGH | Blueprint Studio API authorization bypass for non-admin Home Assistant users |
| CVE-2026-53455 | 8.6 HIGH | Blueprint Studio Git credential helper command injection |
| CVE-2026-53454 | 6.9 MEDIUM | Blueprint Studio stored Git credentials in plaintext Git credential store |
| CVE-2026-53456 | 5.6 MEDIUM | Blueprint Studio terminal SSH private key written to disk |
| CVE-2026-53457 | 5.1 MEDIUM | Blueprint Studio terminal command working directory not bounded to config directory |
No comments yet