漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Nesquena Hermes WebUI Environment Variable Credential Leakage via Profile Switch
Vulnerability Description
nesquena hermes-webui contains an environment variable leakage vulnerability where profile switching does not clear environment variables from the previously active profile before loading the next profile. Attackers or users can exploit additive dotenv reload behavior to access provider API keys and other sensitive secrets from one profile context in another profile, breaking expected security isolation between profiles.
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Vulnerability Type
将资源暴露给错误范围
Vulnerability Title
Hermes Web UI 安全漏洞
Vulnerability Description
Hermes Web UI是Nathan Esquenazi个人开发者的一个轻量级、暗色主题的自主智能体Web界面。 Hermes Web UI存在安全漏洞,该漏洞源于配置文件切换时未在加载下一个配置文件前清除先前活动配置文件的环境变量,可能导致攻击者或用户利用累加式dotenv重新加载行为,破坏配置文件之间的预期安全隔离。
CVSS Information
N/A
Vulnerability Type
N/A