Impact
Based on the description, the likely attack vector is local filesystem access to the Home Assistant configuration directory. Blueprint Studio writes SSH private-key material to a temporary file during terminal SSH authentication. The key is stored under the Home Assistant configuration directory, after which the application attempts to set restrictive permissions and delete the file. If cleanup fails or Home Assistant crashes, the private key may persist on disk. A user or process with read access to the configuration directory could obtain the residual key, potentially granting unauthorized SSH access to connected devices or services. The vulnerability does not allow remote exploitation; it requires local or compromised filesystem access.
Affected Systems
The affected product is Blueprint Studio from ha‑china. Versions prior to 2.5.2 contain the flaw. The fix was released in version 2.5.2 and later releases are safe.
Risk and Exploitability
Based on the description, the likely attack vector is local file system read access to the Home Assistant configuration directory. The CVSS score of 5.6 indicates moderate severity. The EPSS score of <1% reflects a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. The compromise would rely on a local user or process that can read or write files in the Home Assistant configuration directory. The risk is limited to attackers who already have filesystem access, and the attack path does not involve external network access or privilege escalation beyond the local filesystem.
OpenCVE Enrichment