PT-2026-77318 · Home Assistant · Blueprint-Studio

CVE-2026-53458

·

Published

2026-08-18

·

Updated

2026-08-19

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Blueprint Studio versions prior to 2.5.2
Description Backend API handlers in custom components/blueprint studio/backend/api.py return raw exception strings to authenticated Home Assistant users. These exception messages may disclose internal filesystem paths or implementation details, which could allow an authenticated user to fingerprint the installation and refine subsequent attacks.
Recommendations Update to version 2.5.2.

Exploit

Fix

Generation of Error Message Containing Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-53458
GHSA-6VC4-5WQJ-FM6P

Affected Products

Blueprint-Studio