PT-2026-56988 · Unknown · Hermes-Webui

·

CVE-2026-58122

·

Published

2026-07-09

·

Updated

2026-07-10

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Hermes WebUI versions prior to 0.51.307
Description An authentication bypass exists that allows unauthenticated remote attackers to circumvent local-origin IP restrictions on onboarding endpoints. This is achieved by supplying a spoofed X-Forwarded-For header containing a loopback address, which tricks the system into treating the request as local. Successful exploitation enables server-side request forgery (SSRF)—a technique used to induce the server to make requests to an unintended location—against internal services and cloud metadata endpoints. Additionally, attackers can overwrite LLM provider configurations and API keys with controlled values or initiate OAuth device-code flows to obtain persistent access tokens stored in auth.json.
Recommendations Update Hermes WebUI to version 0.51.307.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-58122

Affected Products

Hermes-Webui