CVE-2026-49959
HIGHHermes WebUI < 0.51.311 RCE via Git Configuration Injection
Title source: cnaDescription
Hermes WebUI before version 0.51.311 contains a remote code execution vulnerability that allows authenticated attackers to execute arbitrary commands by placing malicious executable Git configuration in a workspace repository's .git/config file. Attackers can exploit Git subprocess invocations in api/workspace_git.py through vectors such as core.fsmonitor during git status, protocol.ext.allow with ext:: remotes during git fetch, credential.helper, core.askPass, core.gitProxy, or inherited environment variables including GIT_SSH_COMMAND to achieve arbitrary command execution on the host running the application.
References (4)
Core 4
Core References
Release Notes release-notes
https://github.com/nesquena/hermes-webui/releases/tag/v0.51.311
Issue Tracking issue-tracking
https://github.com/nesquena/hermes-webui/pull/3776
Patch patch
https://github.com/nesquena/hermes-webui/commit/938ac9f55b53def1eefb48c4c42dabaf9c22e99c
Third Party Advisory third-party-advisory
https://www.vulncheck.com/advisories/hermes-webui-rce-via-git-configuration-injection
Scores
CVSS v3
8.8
EPSS
0.0032
EPSS Percentile
55.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-78
Status
published
Products (1)
nesquena/hermes-webui
< 0.51.311
Published
Jun 09, 2026
Tracked Since
Jun 09, 2026