PT-2026-77315 · Home Assistant · Blueprint-Studio
CVE-2026-53455
·
Published
2026-08-18
·
Updated
2026-08-19
CVSS v4.0
8.6
High
| Vector | AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Blueprint Studio versions prior to 2.5.2
Description
Blueprint Studio generates a shell-based Git credential helper in the
custom components/blueprint studio/backend/git manager.py file by interpolating the configured Git username and token directly into the executable helper script content without validating the credential values. An attacker capable of setting Git credentials could include newline characters or shell syntax in the username or token variables. When Git executes the generated credential helper, the injected shell commands run with the operating-system privileges of Home Assistant, potentially allowing unauthorized access to or modification of Home Assistant configuration data.Recommendations
Update Blueprint Studio to version 2.5.2.
Exploit
Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Blueprint-Studio