PT-2026-77314 · Unknown · Blueprint-Studio

CVE-2026-53454

·

Published

2026-08-18

·

Updated

2026-08-21

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Blueprint Studio versions prior to 2.5.2
Description Blueprint Studio improperly configures the Git credential.helper store when saving credentials. This causes the system to persist usernames and access tokens in plaintext within the .git-credentials file of the user running Home Assistant. Consequently, these tokens may be accessed by other users or processes sharing the same filesystem context. This persistent configuration also impacts subsequent Git operations performed outside of Blueprint Studio.
Recommendations Update Blueprint Studio to version 2.5.2.

Exploit

Fix

Insufficiently Protected Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-53454
GHSA-PGXQ-H2PC-GQQ8

Affected Products

Blueprint-Studio