Impact
The vulnerability in Blueprint Studio allows any authenticated Home Assistant user who is not an administrator to access a range of backend API actions that were intended only for administrators. This flaw can be exploited to invoke arbitrary Home Assistant services, expose sensitive state data through templates, modify configuration files, and perform file or stream operations. The potential consequence is full compromise of confidentiality, integrity, and availability for the affected Home Assistant installation.
Affected Systems
Blueprint Studio, a VS Code‑like editor for Home Assistant configuration, is affected. The issue exists in all releases prior to version 2.5.2. The problem is resolved in 2.5.2 and later.
Risk and Exploitability
The CVSS score of 8.7 indicates a high‑severity risk. Exploitation requires the attacker to be a legitimate, non‑admin user of the system, which is a realistic scenario for compromised or stolen credentials. The EPSS score is < 1%, and the vulnerability is not listed in the CISA KEV catalog. Given the explicit authorization bypass, the attack vector is through authenticated channels where the attacker can bypass privilege checks to perform unauthorized administrative actions.
OpenCVE Enrichment