PT-2026-77313 · Home Assistant · Blueprint-Studio
CVE-2026-53453
·
Published
2026-08-18
·
Updated
2026-08-19
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Blueprint Studio versions prior to 2.5.2
Description
Blueprint Studio fails to consistently enforce the admin-only authorization boundary on its backend, allowing any authenticated Home Assistant user to access actions intended for administrators. This issue affects several surfaces, including the backend API, upload API, stream routes, terminal WebSocket, and Blueprint Studio WebSocket subscriptions. Specifically, the
call service, render template, and global replace functions, as well as file and stream access paths, upload handling, and terminal helpers, are exposed. An attacker with non-admin privileges could invoke arbitrary Home Assistant services, expose system state via templates, modify configuration files, access streamed or downloaded content, upload files, or access terminal-related helpers, potentially compromising the confidentiality, integrity, and availability of the installation.Recommendations
Update to version 2.5.2.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Blueprint-Studio