What is CVE-2026-53456?
Blueprint Studio before version 2.5.2 writes SSH private key material to a file under the Home Assistant configuration directory, exposing sensitive authentication data. This affects Home Assistant users leveraging Blueprint Studio's terminal SSH feature. Users should immediately update to version 2.5.2 and rotate any exposed SSH keys.
Azərbaycanca: Blueprint Studio 2.5.2-dən əvvəlki versiyalarda SSH autentifikasiya məlumatlarını Home Assistant konfiqurasiya kataloqunda mətn faylına yazaraq SSH özəl açarını ifşa edir. Bu, Blueprint Studio istifadə edən Home Assistant istifadəçilərinə təsir göstərir. İstifadəçilər dərhal Blueprint Studio-nu 2.5.2 versiyasına yeniləməli və təsirlənmiş SSH açarlarını dəyişdirməlidir.
Related CVEs
link basis: same weakness class CWE-798
FAQ2
Which versions of Blueprint Studio are affected by CVE-2026-53456?
Blueprint Studio versions before 2.5.2 are affected.
What should users do to mitigate CVE-2026-53456?
Users should immediately update Blueprint Studio to version 2.5.2 and rotate any exposed SSH keys.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.