PT-2026-53925 · Unknown · Hermes-Webui
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Hermes WebUI versions prior to 0.51.521
Description
An authorization bypass occurs during the session import process. The
/api/session/import endpoint validates the workspace of an imported session under the active named profile but fails to set the profile when constructing the Session object. Consequently, the session is saved with a null profile. Since the profile authorization check treats a null profile as the default profile, a user assigned to the default profile can export the session transcript and use the session identifier to access files from the named profile's workspace, bypassing profile isolation.Recommendations
Update Hermes WebUI to version 0.51.521 or later.
Exploit
Fix
Incorrect Permission
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hermes-Webui