CVE-2026-55197
⚪ Do wiadomości
Luka w Hermes WebUI umożliwia ujawnienie transkryptów sesji innych profili przez uwierzytelnionych użytkowników.
CVSS
6.5
EPSS
0.3%
Exploit
none
Vendor
Opis źródłowy (NVD)
Hermes WebUI before 0.51.443 contains a broken access control vulnerability in the /api/session endpoint that allows authenticated users to disclose cross-profile session transcripts. Attackers can bypass profile boundary checks by directly querying session IDs belonging to other profiles via GET /api/session?session_id=<foreign_id>&messages=1 to retrieve unauthorized conversation transcripts and metadata.
brak
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 6.5 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.3% |
| Opublikowano (NVD) | 2026-06-17 19:18:13 UTC |
| Ostatnia modyfikacja (NVD) | 2026-09-17 18:16:48 UTC |
Referencje
- https://github.com/nesquena/hermes-webui/commit/2a3baa71b81ca92da8ece8616a09f15894beec71 ([email protected])
- https://github.com/nesquena/hermes-webui/pull/3982 ([email protected])
- https://github.com/nesquena/hermes-webui/pull/4269 ([email protected])
- https://github.com/nesquena/hermes-webui/releases/tag/v0.51.443 ([email protected])
- https://www.vulncheck.com/advisories/hermes-webui-broken-access-control-in-api-session-endpoint ([email protected])