PT-2026-48121 · Git+1 · Hermes-Webui

CVE-2026-49959

·

Published

2026-06-09

·

Updated

2026-06-09

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Hermes WebUI versions prior to 0.51.311
Description Authenticated attackers can achieve remote code execution on the host running the application by placing malicious executable Git configuration within a workspace repository's .git/config file. The issue stems from Git subprocess invocations in the api/workspace git.py endpoint. Exploitation vectors include core.fsmonitor during git status, protocol.ext.allow with ext:: remotes during git fetch, credential.helper, core.askPass, core.gitProxy, or inherited environment variables such as GIT SSH COMMAND.
Recommendations Update Hermes WebUI to version 0.51.311 or later.

Exploit

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-49959

Affected Products

Hermes-Webui