PT-2026-77314 · Unknown · Blueprint-Studio
CVE-2026-53454
·
Published
2026-08-18
·
Updated
2026-08-21
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Blueprint Studio versions prior to 2.5.2
Description
Blueprint Studio improperly configures the Git
credential.helper store when saving credentials. This causes the system to persist usernames and access tokens in plaintext within the .git-credentials file of the user running Home Assistant. Consequently, these tokens may be accessed by other users or processes sharing the same filesystem context. This persistent configuration also impacts subsequent Git operations performed outside of Blueprint Studio.Recommendations
Update Blueprint Studio to version 2.5.2.
Exploit
Fix
Insufficiently Protected Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Blueprint-Studio