CVE-2026-53456: CWE-522: Insufficiently Protected Credentials in ha-china blueprint-studio
CVE-2026-53456 is a medium severity vulnerability in ha-china's blueprint-studio prior to version 2.5.2. The issue involves insufficient protection of SSH private key credentials used for terminal authentication. The private key was written to a file in the Home Assistant configuration directory with a best-effort cleanup approach, which could fail or be interrupted, leaving the key accessible on disk. This residual key could be accessed by any user or process with filesystem access to the configuration directory. The vulnerability is fixed in version 2.5.2.
AI Analysis
Technical Summary
Blueprint Studio, a VS Code-like editor for Home Assistant configuration files, used SSH key authentication for its terminal feature. Before version 2.5.2, the SSH private key was temporarily written to disk under the Home Assistant configuration directory with restrictive permissions applied only after writing, and cleanup was best-effort. If cleanup failed or Home Assistant crashed, the private key could remain on disk, exposing it to any user or process with access to the configuration directory. This constitutes insufficient protection of credentials (CWE-522). The issue is resolved in version 2.5.2.
Potential Impact
An attacker or unauthorized user with access to the Home Assistant configuration directory could obtain the SSH private key used for terminal authentication, potentially allowing unauthorized terminal access or lateral movement within the system. The vulnerability requires local filesystem access and elevated privileges to exploit, limiting remote exploitation. The CVSS 4.0 score is 5.6 (medium severity).
Mitigation Recommendations
Upgrade blueprint-studio to version 2.5.2 or later, where the issue is fixed. No other mitigation is indicated or necessary once the update is applied.
CVE-2026-53456: CWE-522: Insufficiently Protected Credentials in ha-china blueprint-studio
Description
CVE-2026-53456 is a medium severity vulnerability in ha-china's blueprint-studio prior to version 2.5.2. The issue involves insufficient protection of SSH private key credentials used for terminal authentication. The private key was written to a file in the Home Assistant configuration directory with a best-effort cleanup approach, which could fail or be interrupted, leaving the key accessible on disk. This residual key could be accessed by any user or process with filesystem access to the configuration directory. The vulnerability is fixed in version 2.5.2.
CVSS v4.0
Score 5.6medium
Affected software
ha-china
blueprint-studio
pkg:github/ha-china/blueprint-studioRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Blueprint Studio, a VS Code-like editor for Home Assistant configuration files, used SSH key authentication for its terminal feature. Before version 2.5.2, the SSH private key was temporarily written to disk under the Home Assistant configuration directory with restrictive permissions applied only after writing, and cleanup was best-effort. If cleanup failed or Home Assistant crashed, the private key could remain on disk, exposing it to any user or process with access to the configuration directory. This constitutes insufficient protection of credentials (CWE-522). The issue is resolved in version 2.5.2.
Potential Impact
An attacker or unauthorized user with access to the Home Assistant configuration directory could obtain the SSH private key used for terminal authentication, potentially allowing unauthorized terminal access or lateral movement within the system. The vulnerability requires local filesystem access and elevated privileges to exploit, limiting remote exploitation. The CVSS 4.0 score is 5.6 (medium severity).
Mitigation Recommendations
Upgrade blueprint-studio to version 2.5.2 or later, where the issue is fixed. No other mitigation is indicated or necessary once the update is applied.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-06-09T16:31:21.495Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6a84ca1cc6e8be0332c0b1ce
Added to database: 08/18/2026, 21:09:48 UTC
Last enriched: 09/11/2026, 14:19:37 UTC
Last updated: 10/03/2026, 14:46:08 UTC
Views: 64
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.