PT-2026-34193 · Nesquena · Hermes-Webui

Published

2026-04-21

·

Updated

2026-04-26

·

CVE-2026-6829

CVSS v3.1

6.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions nesquena hermes-webui (affected versions not specified)
Description A trust-boundary failure allows authenticated attackers to set or change a session workspace to an arbitrary existing directory on disk. This is achieved by manipulating workspace path parameters in the endpoints "/api/session/new", "/api/session/update", "/api/chat/start", and "/api/workspaces/add". Attackers can repoint a session workspace to a directory outside the intended trusted root and use ordinary file read and write APIs to access or modify files outside the intended workspace boundary within the permissions of the hermes-webui process.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2026-6829

Affected Products

Hermes-Webui