---
id: CVE-2026-53454
title: >-
  Blueprint Studio is a VS Code-like file editor for Home Assistant
  configuration files
summary: >-
  Blueprint Studio is a VS Code-like file editor for Home Assistant
  configuration files. Prior to 2.5.2, Blueprint Studio configured Git's
  credential.helper store when saving Git credentials, causing Git
  credential-store to persist usernam…
severity: none
cwe:
  - CWE-522
published: '2026-08-18'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T21:02:26.047'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-53454'
references:
  - url: >-
      https://github.com/ha-china/blueprint-studio/commit/943aed0be67f3a910b0f70a3864288d5e17e55ce
    label: security-advisories@github.com
  - url: 'https://github.com/ha-china/blueprint-studio/releases/tag/v2.5.2'
    label: security-advisories@github.com
  - url: >-
      https://github.com/ha-china/blueprint-studio/security/advisories/GHSA-pgxq-h2pc-gqq8
    label: security-advisories@github.com
tags:
  - nvd
epss: 0.00458
epssPercentile: 0.36967
ingestedAt: '2026-08-22T13:32:37.106Z'
---

## Overview

Blueprint Studio is a VS Code-like file editor for Home Assistant configuration files. Prior to 2.5.2, Blueprint Studio configured Git's credential.helper store when saving Git credentials, causing Git credential-store to persist usernames and access tokens in plaintext in the .git-credentials file for the user running Home Assistant. Tokens could remain outside Blueprint Studio's intended Home Assistant storage and be read by other users or processes with access to the same filesystem context. The persistent helper configuration also affected later Git operations beyond the immediate Blueprint Studio action. This issue is fixed in version 2.5.2.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
