Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 CVE-2026-53457 is a path traversal vulnerability in ha-china blueprint-studio prior to version 2.5.2. The vulnerability arises from improper validation of a working-directory parameter in the terminal command execution path, allowing an administrator to specify directories outside the intended Home Assistant configuration directory. This could enable commands to access or modify files beyond the expected restricted filesystem area. The issue is fixed in version 2.5.2. Join the discussion | CVE Database V5 | 08/18/2026, 20:51:01 UTC Added: 08/18/2026, 21:09:48 UTC |
0 CVE-2026-53456 is a medium severity vulnerability in ha-china's blueprint-studio prior to version 2.5.2. The issue involves insufficient protection of SSH private key credentials used for terminal authentication. The private key was written to a file in the Home Assistant configuration directory with a best-effort cleanup approach, which could fail or be interrupted, leaving the key accessible on disk. This residual key could be accessed by any user or process with filesystem access to the configuration directory. The vulnerability is fixed in version 2.5.2. Join the discussion | CVE Database V5 | 08/18/2026, 20:50:21 UTC Added: 08/18/2026, 21:09:48 UTC |
CVE-2026-53455 is an OS command injection vulnerability in ha-china's Blueprint Studio, a VS Code-like editor for Home Assistant configuration files. Versions prior to 2.5.2 generate a shell-based Git credential helper by directly embedding user-configured Git usernames and tokens without validation. This allows an attacker who can set Git credentials to inject shell commands via special characters in the username or token. When Git runs the helper, the injected commands execute with Home Assistant's OS privileges, potentially accessing or modifying configuration data. The issue is fixed in version 2.5.2. Join the discussion | CVE Database V5 | 08/18/2026, 20:49:36 UTC Added: 08/18/2026, 21:09:48 UTC |
0 Blueprint Studio, a VS Code-like editor for Home Assistant configuration files, prior to version 2.5.2, stored Git credentials in plaintext in the .git-credentials file due to configuring Git's credential.helper store. This caused usernames and access tokens to be persistently saved outside the intended secure storage, making them accessible to other users or processes with filesystem access. The issue was fixed in version 2.5.2. Join the discussion | CVE Database V5 | 08/18/2026, 20:48:58 UTC Added: 08/18/2026, 21:09:48 UTC |
Blueprint Studio, a VS Code-like editor for Home Assistant configuration files, had a missing authorization vulnerability prior to version 2.5.2. This flaw allowed any authenticated Home Assistant user, not just administrators, to access backend API actions intended for admins only. Exploitable surfaces included APIs for uploading, streaming, terminal WebSocket, service calls, template rendering, file access, and more. A non-admin user could perform unauthorized actions such as invoking arbitrary services, modifying configuration files, and accessing sensitive data, potentially compromising the confidentiality, integrity, and availability of the Home Assistant installation. The issue is fixed in version 2.5.2. Join the discussion | CVE Database V5 | 08/18/2026, 20:48:20 UTC Added: 08/18/2026, 21:09:46 UTC |
0 CVE-2026-53458 is a vulnerability in the ha-china blueprint-studio, a VS Code-like editor for Home Assistant configuration files. Versions prior to 2.5.2 expose raw exception messages containing sensitive information such as internal filesystem paths and implementation details to authenticated users. This information disclosure could aid attackers in fingerprinting the Home Assistant installation and planning further attacks. The issue is resolved in version 2.5.2. Join the discussion | CVE Database V5 | 08/18/2026, 20:47:25 UTC Added: 08/18/2026, 21:09:48 UTC |
Showing 1 to 6 of 6 results