PT-2026-50523 · Unknown · Hermes-Webui
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Hermes WebUI versions prior to 0.51.443
Description
An authorization bypass exists in the session export endpoint, allowing authenticated users to access sessions belonging to other profiles. The
handle session export() function in 'api/routes.py' does not verify ownership of the active profile before serializing session data. This allows attackers to exfiltrate session transcripts from other users by knowing or guessing session identifiers.Recommendations
Update to version 0.51.443 or later.
Exploit
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hermes-Webui