PT-2026-77316 · Home Assistant · Blueprint-Studio

CVE-2026-53456

·

Published

2026-08-18

·

Updated

2026-08-18

CVSS v4.0

5.6

Medium

VectorAV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Blueprint Studio versions prior to 2.5.2
Description Blueprint Studio, a file editor for Home Assistant configuration files, handles SSH key authentication in the terminal manager.py file within the custom components/blueprint studio/backend/ directory. The software writes SSH private-key material to a file in the Home Assistant configuration directory before applying restrictive permissions and relies on a best-effort cleanup process. Consequently, the private key may temporarily remain on the disk or persist if the cleanup fails or the system crashes, allowing a user or process with filesystem access to the configuration directory to obtain the residual private key.
Recommendations Update to version 2.5.2.

Exploit

Fix

Insufficiently Protected Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-53456
GHSA-3VG8-XF27-7Q45

Affected Products

Blueprint-Studio