Hermes Web UI是Nathan Esquenazi个人开发者的一个轻量级、暗色主题的自主智能体Web界面。 Hermes Web UI 0.51.270之前版本存在安全漏洞,该漏洞源于资源耗尽问题,可能导致未经身份验证的远程攻击者通过重复调用passkey options端点降低服务可用性。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| nesquena | hermes-webui | < 0.51.270 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| nesquena | hermes-webui | 0 ~ 0.51.270 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-49959 | 8.8 HIGH | Hermes WebUI < 0.51.311 RCE via Git Configuration Injection |
| CVE-2026-49957 | 7.7 HIGH | Hermes WebUI < 0.51.296 Workspace Boundary Bypass via api/workspace.py |
| CVE-2026-49956 | 6.5 MEDIUM | Hermes WebUI < 0.51.269 Profile Isolation Bypass via sessions search |
| CVE-2026-49958 | 5.0 MEDIUM | Hermes WebUI < 0.51.303 TOCTOU Race Condition via git_discard |
No comments yet