PT-2026-48121 · Nesquena · Hermes-Webui

Published

2026-06-09

·

Updated

2026-06-09

·

CVE-2026-49959

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Hermes WebUI before version 0.51.311 contains a remote code execution vulnerability that allows authenticated attackers to execute arbitrary commands by placing malicious executable Git configuration in a workspace repository's .git/config file. Attackers can exploit Git subprocess invocations in api/workspace git.py through vectors such as core.fsmonitor during git status, protocol.ext.allow with ext:: remotes during git fetch, credential.helper, core.askPass, core.gitProxy, or inherited environment variables including GIT SSH COMMAND to achieve arbitrary command execution on the host running the application.

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2026-49959

Affected Products

Hermes-Webui