PT-2026-77318 · Home Assistant · Blueprint-Studio
CVE-2026-53458
·
Published
2026-08-18
·
Updated
2026-08-19
CVSS v4.0
5.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Blueprint Studio versions prior to 2.5.2
Description
Backend API handlers in
custom components/blueprint studio/backend/api.py return raw exception strings to authenticated Home Assistant users. These exception messages may disclose internal filesystem paths or implementation details, which could allow an authenticated user to fingerprint the installation and refine subsequent attacks.Recommendations
Update to version 2.5.2.
Exploit
Fix
Generation of Error Message Containing Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Blueprint-Studio