PatchSiren

ha-china CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM ha-china CVE published 2026-08-18

CVE-2026-53458

CVE-2026-53458 debrief: Blueprint Studio backend API handlers returned raw exception strings to authenticated users, potentially aiding fingerprinting and follow-up attacks by disclosing internal filesystem paths or implementation details. This issue is fixed in version 2.5.2. Affected users should assess exposure and update to prevent potential exploitation. The vulnerability allows authenticated Bluepri [truncated]

MEDIUM ha-china CVE published 2026-08-18

CVE-2026-53457

PatchSiren debrief for CVE-2026-53457: Blueprint Studio for Home Assistant configuration files has a medium-severity vulnerability allowing an administrator to access or modify host paths outside the intended configuration boundary due to improper validation of the working directory parameter in the terminal command execution path. This issue is fixed in version 2.5.2.

MEDIUM ha-china CVE published 2026-08-18

CVE-2026-53456

CVE-2026-53456 is a vulnerability in Blueprint Studio, a VS Code-like file editor for Home Assistant configuration files. Prior to version 2.5.2, the terminal SSH key authentication feature wrote SSH private-key material to a file under the Home Assistant configuration directory before applying restrictive permissions. This could allow a user or process with filesystem access to the Home Assistant configu [truncated]

HIGH ha-china CVE published 2026-08-18

CVE-2026-53455

CVE-2026-53455 is a high-severity vulnerability in Blueprint Studio, a VS Code-like file editor for Home Assistant configuration files. The issue allows an attacker to inject shell commands by including newline characters or shell syntax in Git credentials, which can lead to access or modification of Home Assistant configuration data. This vulnerability is caused by Blueprint Studio generating a shell-bas [truncated]

MEDIUM ha-china CVE published 2026-08-18

CVE-2026-53454

Blueprint Studio, a VS Code-like file editor for Home Assistant configuration files, had a vulnerability prior to version 2.5.2. The issue allowed Git credential-store to persist usernames and access tokens in plaintext in the .git-credentials file when saving Git credentials. This vulnerability could lead to unauthorized access to Git repositories and sensitive information. Home Assistant users and admin [truncated]

HIGH ha-china CVE published 2026-08-18

CVE-2026-53453

CVE-2026-53453 debrief based on the supplied source corpus. Blueprint Studio, a VS Code-like file editor for Home Assistant configuration files, exposed administrator-intended backend API actions to any authenticated Home Assistant user prior to version 2.5.2. This allowed non-admin users to invoke arbitrary Home Assistant services, expose Home Assistant state through templates, modify configuration files [truncated]