PT-2026-34195 · Unknown · Hermes-Webui
Hinotoi-Agent
·
Published
2026-04-21
·
Updated
2026-06-04
·
CVE-2026-6832
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Hermes WebUI (affected versions not specified)
Description
An arbitrary file deletion issue exists in the '/api/session/delete' endpoint. Authenticated attackers can delete files outside the session directory by providing an absolute path or path traversal payload in the
session id parameter. This occurs because unvalidated session identifiers allow the construction of paths that bypass the SESSION DIR boundary, enabling the deletion of writable JSON files on the host system.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hermes-Webui