โ† All reports

The nesquena hermes-webui product has a vulnerability that allows authenticated attackers to delete files outside the session directory.

CybersecurityTechnologyConflictApr 22, 2026score 0.172 posts ยท 0 replies across 1 instances
The thread discusses two vulnerabilities in the nesquena hermes-webui product, highlighting an arbitrary file deletion vulnerability and an environment variable leakage issue. These vulnerabilities pose security risks to users and require attention from developers and administrators.

Claims

The nesquena hermes-webui product has a vulnerability that allows authenticated attackers to delete files outside the session directory.
Parent: CybersecurityEntity: nesquena hermes-webuiImpact: negativeDate: Apr 22, 2026Target: The security of the nesquena hermes-webui product
The nesquena hermes-webui product has an environment variable leakage vulnerability that can be exploited by attackers or users.
Parent: CybersecurityEntity: nesquena hermes-webuiImpact: negativeDate: Apr 22, 2026Target: The security of the nesquena hermes-webui product

Source posts

@[email protected]
๐Ÿšจ EUVD-2026-24515 ๐Ÿ“Š Score: 4.8/10 (CVSS v3.1) ๐Ÿ“ฆ Product: hermes-webui ๐Ÿข Vendor: nesquena ๐Ÿ“… Updated: 2026-04-21 ๐Ÿ“ nesquena hermes-webui contains an environment variable leakage vulnerability where profile switching does not clear environment variables from the previously active profile before loading the next profile. Attackers or users can exploit additive dotenv... ๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24515 #cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 22, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
@[email protected]
๐Ÿšจ EUVD-2026-24517 ๐Ÿ“Š Score: 7.2/10 (CVSS v3.1) ๐Ÿ“ฆ Product: hermes-webui ๐Ÿข Vendor: nesquena ๐Ÿ“… Updated: 2026-04-21 ๐Ÿ“ Hermes WebUI contains an arbitrary file deletion vulnerability in the /api/session/delete endpoint that allows authenticated attackers to delete files outside the session directory by supplying an absolute path or path traversal payload in the session_... ๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24517 #cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 22, 2026
#cybersecurity#infosec#euvd#cve#vulnerability