Impact
Blueprint Studio’s backend API returned raw exception strings to any authenticated Home Assistant user until version 2.5.2. Some of those exception messages contained internal filesystem paths or internal implementation details. This exposure allows an authenticated user to fingerprint the Home Assistant installation, which can then aid in planning subsequent attacks. The vulnerability represents an information‑disclosure issue (CWE‑209) and does not grant the attacker additional privileges beyond what an authenticated user already possesses.
Affected Systems
The affected product is the Home Assistant custom component Blueprint Studio from the vendor ha‑china. Versions older than 2.5.2 are vulnerable. All installations of Blueprint Studio that have not applied the 2.5.2 update are at risk.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. An EPSS score of 0.00339 (approximately 0.34%) indicates a very low probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog, suggesting limited knowledge of active exploitation. The attack vector is restricted to users who are already authenticated to Home Assistant; an unauthenticated attacker cannot trigger the vulnerability. However, because the information revealed can help refine further attacks, the risk to the overall system remains moderate when the underlying authentication is compromised or poorly protected.
OpenCVE Enrichment