PT-2026-77315 · Home Assistant · Blueprint-Studio

CVE-2026-53455

·

Published

2026-08-18

·

Updated

2026-08-19

CVSS v4.0

8.6

High

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Blueprint Studio versions prior to 2.5.2
Description Blueprint Studio generates a shell-based Git credential helper in the custom components/blueprint studio/backend/git manager.py file by interpolating the configured Git username and token directly into the executable helper script content without validating the credential values. An attacker capable of setting Git credentials could include newline characters or shell syntax in the username or token variables. When Git executes the generated credential helper, the injected shell commands run with the operating-system privileges of Home Assistant, potentially allowing unauthorized access to or modification of Home Assistant configuration data.
Recommendations Update Blueprint Studio to version 2.5.2.

Exploit

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-53455
GHSA-WJPC-MC3F-W5RG

Affected Products

Blueprint-Studio