PT-2026-56988 · Unknown · Hermes-Webui
CVSS v4.0
9.3
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Hermes WebUI versions prior to 0.51.307
Description
An authentication bypass exists that allows unauthenticated remote attackers to circumvent local-origin IP restrictions on onboarding endpoints. This is achieved by supplying a spoofed
X-Forwarded-For header containing a loopback address, which tricks the system into treating the request as local. Successful exploitation enables server-side request forgery (SSRF)—a technique used to induce the server to make requests to an unintended location—against internal services and cloud metadata endpoints. Additionally, attackers can overwrite LLM provider configurations and API keys with controlled values or initiate OAuth device-code flows to obtain persistent access tokens stored in auth.json.Recommendations
Update Hermes WebUI to version 0.51.307.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hermes-Webui