nesquena Hermes WebUI是nesquena的Web服务器。 Nathan Esquenazi Hermes WebUI 0.51.443之前版本存在授权问题漏洞,该漏洞源于/api/session端点存在访问控制漏洞,可能导致经过身份验证的用户通过直接查询其他配置文件的session ID来跨配置文件泄露会话记录。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| nesquena | hermes-webui | < 0.51.443 |
affected |
0.51.443 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| nesquena | hermes-webui | 0 ~ 0.51.443 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-53871 | 8.1 HIGH | Hermes WebUI < 0.51.368 - Profile-Scoped Authorization Bypass via Forged hermes_profile Co |
| CVE-2026-55198 | 6.5 MEDIUM | Hermes WebUI < 0.51.443 - Cross-Profile Session Data Exfiltration via Session Export Endpo |
No comments yet