Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

hermes-webui — Vulnerabilities & Security Advisories 18

All 18 CVE vulnerabilities found in hermes-webui, with AI-generated Chinese analysis, references, and POCs.

This page aggregates security vulnerability data for hermes-webui, focusing on implementation flaws within the application’s web interface and backend logic. It collects various weakness types, including injection attacks, access control failures, and sensitive data exposure, covering incidents reported from the product’s initial release through the most recent public advisories. Visitors can track the vendor’s response patterns over time, analyze the frequency of specific weakness classes such as cross-site scripting or insecure direct object references, and review the complete vulnerability history of the hermes-webui software stack. The dataset highlights recurring issues in authentication mechanisms and input validation, providing a clear view of the product’s security posture without filtering out lower-severity findings. By examining these records, developers and security professionals can identify common attack vectors targeting this specific web-based management tool and compare its stability against similar open-source web interfaces. The collection is continuously updated as new reports are verified, ensuring that the historical record remains accurate and useful for longitudinal security analysis.

Vendor: nesquena

CVE ID Title CVSS Severity Published
CVE-2026-58122 Hermes WebUI < 0.51.307 Authentication Bypass via X-Forwarded-For Header Spoofing CWE-348 9.1 Critical 2026-07-09
CVE-2026-58123 Hermes WebUI < 0.51.788 Unauthenticated RCE via Terminal API CWE-306 9.8 Critical 2026-07-09
CVE-2026-58174 Hermes WebUI < 0.51.521 - Cross-Profile Authorization Bypass via Unset Session Profile on Import CWE-732 6.5 Medium 2026-06-30
CVE-2026-55205 Hermes WebUI < 0.51.468 - Resource Exhaustion via Unauthenticated OAuth Flow Endpoint CWE-770 5.3 Medium 2026-06-18
CVE-2026-55198 Hermes WebUI < 0.51.443 - Cross-Profile Session Data Exfiltration via Session Export Endpoint CWE-639 6.5 Medium 2026-06-17
CVE-2026-55197 Hermes WebUI < 0.51.443 - Broken Access Control in /api/session Endpoint CWE-639 6.5 Medium 2026-06-17
CVE-2026-55196 Hermes WebUI < 0.51.409 - Unauthenticated Passkey Registration via Authentication Bypass CWE-306 9.1 Critical 2026-06-17
CVE-2026-53871 Hermes WebUI < 0.51.368 - Profile-Scoped Authorization Bypass via Forged hermes_profile Cookie CWE-565 8.1 High 2026-06-17
CVE-2026-49973 Hermes WebUI < 0.51.358 Unauthenticated Password Takeover via /api/settings CWE-306 9.4 Critical 2026-06-11
CVE-2026-49959 Hermes WebUI < 0.51.311 RCE via Git Configuration Injection CWE-78 8.8 High 2026-06-09
CVE-2026-49958 Hermes WebUI < 0.51.303 TOCTOU Race Condition via git_discard CWE-367 5.0 Medium 2026-06-09
CVE-2026-49957 Hermes WebUI < 0.51.296 Workspace Boundary Bypass via api/workspace.py CWE-22 7.7 High 2026-06-09
CVE-2026-49956 Hermes WebUI < 0.51.269 Profile Isolation Bypass via sessions search CWE-862 6.5 Medium 2026-06-09
CVE-2026-49955 Hermes WebUI < 0.51.270 Resource Exhaustion via passkey/options CWE-770 5.3 Medium 2026-06-09
CVE-2026-22677 Hermes WebUI < 0.51.44 Path Traversal via Session Import Endpoint CWE-22 6.5 Medium 2026-05-13
CVE-2026-6832 Nesquena Hermes WebUI Arbitrary File Deletion via Unvalidated session_id CWE-22 8.1 High 2026-04-21
CVE-2026-6830 Nesquena Hermes WebUI Environment Variable Credential Leakage via Profile Switch CWE-668 3.3 Low 2026-04-21
CVE-2026-6829 nesquena hermes-webui Arbitrary Workspace Directory Access CWE-22 6.3 Medium 2026-04-21

All 18 known CVE vulnerabilities affecting hermes-webui with full Chinese analysis, references, and POCs where available.