What is CVE-2026-53454?
CVE-2026-53454 affects Blueprint Studio, a file editor for Home Assistant. Prior to version 2.5.2, it used Git's credential.helper store, causing usernames and access tokens to be persisted in plaintext within the .git-credentials file. Users must update to version 2.5.2 and clear any affected .git-credentials files.
Azərbaycanca: CVE-2026-53454 Home Assistant üçün Blueprint Studio fayl redaktorunda aşkarlanıb. 2.5.2 versiyasından əvvəl Git kredensiallarını saxlayarkən credential.helper store istifadə edildiyi üçün istifadəçi adı və access token .git-credentials faylında açıq mətndə saxlanır. İstifadəçilər dərhal 2.5.2 versiyasına yeniləməli və təsirlənmiş faylı təmizləməlidir.
Related CVEs
link basis: same weakness class CWE-522
FAQ2
Why does CVE-2026-53454 occur in Blueprint Studio?
The vulnerability occurs because Blueprint Studio versions prior to 2.5.2 use Git's credential.helper store mechanism, causing usernames and access tokens to be persisted in plaintext within the .git-credentials file.
What should I do to protect against CVE-2026-53454?
You must immediately update Blueprint Studio to version 2.5.2 and clear any affected .git-credentials files.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.