What is CVE-2026-53455?
This vulnerability affects the Blueprint Studio add-on for Home Assistant. The `git_manager.py` file constructs a shell-based Git credential helper by directly interpolating the username and token, which could lead to remote code execution (RCE). Upgrading to version 2.5.2 is recommended.
Azərbaycanca: Bu zəiflik Home Assistant-ın Blueprint Studio əlavəsində aşkarlanıb. `git_manager.py` faylında Git istifadəçi adı və token birbaşa shell əmrinə daxil edildiyi üçün uzaqdan kod icrasına (RCE) yol aça bilər. 2.5.2 versiyasına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-78
FAQ2
Which Home Assistant add-on is affected by CVE-2026-53455?
This vulnerability affects the Blueprint Studio add-on for Home Assistant.
What version is recommended to mitigate CVE-2026-53455?
Upgrading to version 2.5.2 is recommended.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.