PT-2026-77317 · Home Assistant · Blueprint-Studio
CVE-2026-53457
·
Published
2026-08-18
·
Updated
2026-08-18
CVSS v4.0
5.1
Medium
| Vector | AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Blueprint Studio versions prior to 2.5.2
Description
The legacy stateless terminal command execution path in
custom components/blueprint studio/backend/terminal manager.py accepts a cwd working-directory parameter. The system only verifies if the directory exists but does not ensure it remains within the Home Assistant configuration directory. This allows an administrator using the restricted terminal helper to select directories outside the intended boundary, enabling access to or modification of host paths permitted by the Home Assistant container and filesystem permissions.Recommendations
Update to version 2.5.2.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Blueprint-Studio