nesquena-hermes
13 exploits
Active since Apr 2026
Hermes WebUI < 0.51.468 - Resource Exhaustion via Unauthenticated OAuth Flow Endpoint
CVSS 5.3
Hermes WebUI < 0.51.368 - Profile-Scoped Authorization Bypass via Forged hermes_profile Cookie
CVSS 8.1
Hermes WebUI < 0.51.409 - Unauthenticated Passkey Registration via Authentication Bypass
CVSS 9.1
Hermes WebUI < 0.51.443 - Broken Access Control in /api/session Endpoint
CVSS 6.5
Hermes WebUI < 0.51.443 - Cross-Profile Session Data Exfiltration via Session Export Endpoint
CVSS 6.5
Hermes WebUI < 0.51.270 Resource Exhaustion via passkey/options
CVSS 5.3
Hermes WebUI < 0.51.269 Profile Isolation Bypass via sessions search
CVSS 6.5
Hermes WebUI < 0.51.269 Workspace Boundary Bypass via api/workspace.py
CVSS 7.7
Hermes WebUI < 0.51.303 TOCTOU Race Condition via git_discard
CVSS 5.0
Hermes WebUI < 0.51.311 RCE via Git Configuration Injection
CVSS 8.8
Hermes WebUI before 0.51.221 Path Traversal via Symlink Workspace Bypass
CVSS 6.5
nesquena hermes-webui Arbitrary Workspace Directory Access
CVSS 6.3
Nesquena Hermes WebUI Arbitrary File Deletion via Unvalidated session_id
CVSS 8.1