PT-2026-34195 · Unknown · Hermes-Webui

Hinotoi-Agent

·

Published

2026-04-21

·

Updated

2026-06-04

·

CVE-2026-6832

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Hermes WebUI (affected versions not specified)
Description An arbitrary file deletion issue exists in the '/api/session/delete' endpoint. Authenticated attackers can delete files outside the session directory by providing an absolute path or path traversal payload in the session id parameter. This occurs because unvalidated session identifiers allow the construction of paths that bypass the SESSION DIR boundary, enabling the deletion of writable JSON files on the host system.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-6832

Affected Products

Hermes-Webui