Junglewise Threat Intelligence

CVE-2026-22677: nesquena Hermes WebUI path traversal in session import endpoint

CVE-2026-22677 · Severity: medium · CVSS 6.5 · Published 2026-05-13

Technologies: Nesquena Hermes WebUI. Vendors: Nesquena.

Executive brief

Hermes WebUI, a web interface for managing sessions and workspaces, contains a security flaw in how it handles imported session files. An authenticated user can upload a specially crafted session file that bypasses directory restrictions, allowing them to read sensitive files from the underlying server's filesystem. This could lead to the exposure of system configuration files or other private data, potentially compromising the security of the host machine.

Technical details

A path traversal vulnerability exists in the `_handle_session_import()` function within `api/routes.py` of Hermes WebUI. While standard session creation uses `resolve_trusted_workspace()` to validate paths, the session import endpoint previously trusted the `workspace` field from user-supplied JSON directly. An authenticated attacker can import a session with the workspace set to a restricted root (e.g., "/") and subsequently use the session file API (e.g., `/api/file`) with relative paths to read any file accessible by the WebUI process. This issue is resolved in version 0.51.44 by enforcing workspace validation during the import process.

Affected products

  • nesquena Hermes WebUI < 0.51.44

Timeline

  • 2026-05-10: patched: Fix committed to repository.
  • 2026-05-11: advisory: Release v0.51.44 published.
  • 2026-05-13: disclosed: CVE published to NVD.

References

Related threats