The nesquena hermes-webui product has a vulnerability that allows authenticated attackers to delete files outside the session directory.
Claims
The nesquena hermes-webui product has a vulnerability that allows authenticated attackers to delete files outside the session directory.
Parent: CybersecurityEntity: nesquena hermes-webuiImpact: negativeDate: Apr 22, 2026Target: The security of the nesquena hermes-webui product
The nesquena hermes-webui product has an environment variable leakage vulnerability that can be exploited by attackers or users.
Parent: CybersecurityEntity: nesquena hermes-webuiImpact: negativeDate: Apr 22, 2026Target: The security of the nesquena hermes-webui product
Source posts
๐จ EUVD-2026-24515
๐ Score: 4.8/10 (CVSS v3.1)
๐ฆ Product: hermes-webui
๐ข Vendor: nesquena
๐
Updated: 2026-04-21
๐ nesquena hermes-webui contains an environment variable leakage vulnerability where profile switching does not clear environment variables from the previously active profile before loading the next profile. Attackers or users can exploit additive dotenv...
๐ https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24515
#cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 22, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
๐จ EUVD-2026-24517
๐ Score: 7.2/10 (CVSS v3.1)
๐ฆ Product: hermes-webui
๐ข Vendor: nesquena
๐
Updated: 2026-04-21
๐ Hermes WebUI contains an arbitrary file deletion vulnerability in the /api/session/delete endpoint that allows authenticated attackers to delete files outside the session directory by supplying an absolute path or path traversal payload in the session_...
๐ https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24517
#cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 22, 2026
#cybersecurity#infosec#euvd#cve#vulnerability