Unknown · Hermes-Webui · CVE-2026-58122
**Name of the Vulnerable Software and Affected Versions**
Hermes WebUI versions prior to 0.51.307
**Description**
An authentication bypass exists that allows unauthenticated remote attackers to circumvent local-origin IP restrictions on onboarding endpoints. This is achieved by supplying a spoofed `X-Forwarded-For` header containing a loopback address, which tricks the system into treating the request as local. Successful exploitation enables server-side request forgery (SSRF)—a technique used to induce the server to make requests to an unintended location—against internal services and cloud metadata endpoints. Additionally, attackers can overwrite LLM provider configurations and API keys with controlled values or initiate OAuth device-code flows to obtain persistent access tokens stored in `auth.json`.
**Recommendations**
Update Hermes WebUI to version 0.51.307.