What is CVE-2026-53457?
CVE-2026-53457 is a vulnerability in Blueprint Studio (a file editor for Home Assistant) prior to version 2.5.2, caused by improper validation of the working directory (cwd) parameter in the legacy stateless terminal command execution path. This could allow unauthorized command injection, and users should update to version 2.5.2 or later immediately.
Azərbaycanca: CVE-2026-53457 Blueprint Studio əlavəsinin 2.5.2-dən əvvəlki versiyalarında terminal əmrlərinin icrası zamanı işlək qovluq (cwd) parametrinin zəif yoxlanılması səbəbindən yaranan təhlükəsizlik boşluğudur. Bu, Home Assistant istifadəçilərinə təsir edir və hücumçuya icazəsiz əmrlər yeritməyə imkan verə bilər; istifadəçilər dərhal 2.5.2 və ya daha yeni versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-77
FAQ2
What software is affected by CVE-2026-53457?
This vulnerability affects versions of Blueprint Studio, a file editor for Home Assistant, prior to version 2.5.2.
What should I do to mitigate CVE-2026-53457?
You should immediately update the Blueprint Studio add-on to version 2.5.2 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.