Hermes
Hermes Webui: vulnerabilidades y CVE
Hermes Webui tiene 14 vulnerabilidades publicadas, 14 de ellas en los últimos 12 meses. 4 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE14
Últimos 12 meses14
Críticas4
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-58123 | Crítica (9.3) | 4.6% | — | 9 jul 2026 | Hermes WebUI before 0.51.788 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary shell commands by accessing the embedded terminal API endpoints without… |
| CVE-2026-58122 | Crítica (9.3) | 0.37% | — | 9 jul 2026 | Hermes WebUI before 0.51.307 contains an authentication bypass vulnerability that allows unauthenticated remote attackers to circumvent local-origin IP restrictions on onboarding endpoints by supplying a spoofed… |
| CVE-2026-58174 | Media (6) | 0.45% | — | 30 jun 2026 | Hermes WebUI before 0.51.521 validates the workspace of an imported session under the active named profile but constructs the Session object without setting its profile in the /api/session/import handler, so the… |
| CVE-2026-55205 | Media (6.9) | 0.52% | — | 18 jun 2026 | Hermes WebUI before 0.51.468 contains a resource exhaustion vulnerability in the unauthenticated POST /api/onboarding/oauth/start endpoint that allows unbounded accumulation of in-memory flow state and daemon threads.… |
| CVE-2026-55198 | Alta (7.1) | 0.47% | — | 17 jun 2026 | Hermes WebUI before 0.51.443 contains an authorization bypass vulnerability in the session export endpoint that allows authenticated users to access sessions from other profiles. The _handle_session_export handler in… |
| CVE-2026-55197 | Alta (7.1) | 0.47% | — | 17 jun 2026 | Hermes WebUI before 0.51.443 contains a broken access control vulnerability in the /api/session endpoint that allows authenticated users to disclose cross-profile session transcripts. Attackers can bypass profile… |
| CVE-2026-55196 | Crítica (9.1) | 0.82% | — | 17 jun 2026 | Hermes WebUI before 0.51.409 contains an authentication bypass vulnerability in passkey registration endpoints that allows unauthenticated remote attackers to register arbitrary passkeys. When HERMES_WEBUI_PASSKEY=1 is… |
| CVE-2026-53871 | Alta (8.6) | 0.50% | — | 17 jun 2026 | Hermes WebUI before 0.51.368 contains an authorization bypass vulnerability in the get_profile_cookie() function that accepts unauthenticated profile names from the hermes_profile cookie. An authenticated attacker can… |
| CVE-2026-49973 | Crítica (9.2) | 0.73% | — | 11 jun 2026 | Hermes WebUI before version 0.51.358 contains an improper access control vulnerability that allows unauthenticated remote attackers to hijack initial setup by submitting the _set_password parameter to the settings API… |
| CVE-2026-49957 | Media (6.3) | 0.51% | — | 9 jun 2026 | Hermes WebUI before version 0.51.296 contains a workspace boundary bypass vulnerability that allows authenticated attackers to circumvent blocked-root path checks by exploiting an early return in the SSH/remote terminal… |
| CVE-2026-49956 | Alta (7.1) | 0.47% | — | 9 jun 2026 | Hermes WebUI before version 0.51.269 contains a profile isolation bypass vulnerability that allows authenticated users to access data belonging to other profiles by querying the session search endpoint without… |
| CVE-2026-49955 | Media (6.9) | 0.78% | — | 9 jun 2026 | Hermes WebUI before version 0.51.270 contains a resource exhaustion vulnerability that allows unauthenticated remote attackers to degrade service availability by repeatedly calling the passkey options endpoint without… |
| CVE-2026-11322 | Alta (7.1) | 0.32% | — | 4 jun 2026 | Hermes WebUI prior to v0.51.221 contains a path traversal vulnerability that allows attackers to escape the workspace boundary by supplying symlinks that resolve to files or directories outside the designated workspace… |
| CVE-2026-22677 | Media (6) | 0.38% | — | 13 may 2026 | Hermes WebUI prior to 0.51.44 contains a path traversal vulnerability in the session import endpoint that allows authenticated attackers to read arbitrary files by importing a crafted session with an unrestricted… |