PT-2026-77316 · Home Assistant · Blueprint-Studio
CVE-2026-53456
·
Published
2026-08-18
·
Updated
2026-08-18
CVSS v4.0
5.6
Medium
| Vector | AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Blueprint Studio versions prior to 2.5.2
Description
Blueprint Studio, a file editor for Home Assistant configuration files, handles SSH key authentication in the
terminal manager.py file within the custom components/blueprint studio/backend/ directory. The software writes SSH private-key material to a file in the Home Assistant configuration directory before applying restrictive permissions and relies on a best-effort cleanup process. Consequently, the private key may temporarily remain on the disk or persist if the cleanup fails or the system crashes, allowing a user or process with filesystem access to the configuration directory to obtain the residual private key.Recommendations
Update to version 2.5.2.
Exploit
Fix
Insufficiently Protected Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Blueprint-Studio