Hermes WebUI before 0.51.443 contains an authorization bypass vulnerability in the session export endpoint that allows authenticated users to access sessions from other profiles. The _handle_session_export handler in api/routes.py fails to verify active-profile ownership before serializing session data, enabling attackers to exfiltrate foreign session transcripts by guessing or knowing session identifiers.
Metrics
Affected Vendors & Products
References
History
Thu, 18 Jun 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nesquena
Nesquena hermes-webui |
|
| Vendors & Products |
Nesquena
Nesquena hermes-webui |
Thu, 18 Jun 2026 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Hermes WebUI before 0.51.443 contains an authorization bypass vulnerability in the session export endpoint that allows authenticated users to access sessions from other profiles. The _handle_session_export handler in api/routes.py fails to verify active-profile ownership before serializing session data, enabling attackers to exfiltrate foreign session transcripts by guessing or knowing session identifiers. | |
| Title | Hermes WebUI < 0.51.443 - Cross-Profile Session Data Exfiltration via Session Export Endpoint | |
| Weaknesses | CWE-639 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-06-17T19:30:54.755Z
Reserved: 2026-06-16T15:53:37.764Z
Link: CVE-2026-55198
Updated: 2026-06-17T19:30:48.718Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-18T20:45:03Z