CVE-2026-22677: Nesquena Hermes-Webui

Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.

Hermes WebUI prior to 0.51.44 contains a path traversal vulnerability in the session import endpoint that allows authenticated attackers to read arbitrary files by importing a crafted session with an unrestricted workspace value. Attackers can supply a blocked filesystem root in the workspace field and subsequently use relative paths in the session file API to access any file readable by the WebUI process.

Affected products

  • Nesquena Hermes-Webui: before 0.51.44 (fixed in 0.51.44)

Published 2026-05-13. Last modified 2026-07-14.