Executive brief
Hermes WebUI, a web interface for managing sessions, contains a security flaw that allows logged-in users to delete arbitrary files on the server. By sending a specially crafted request to the session deletion endpoint, an attacker can bypass intended restrictions and remove critical system or application files. This could lead to data loss, service disruption, or the corruption of application state.
Technical details
An arbitrary file deletion vulnerability exists in Hermes WebUI due to improper validation of the 'session_id' parameter in the '/api/session/delete' endpoint. The application uses the user-provided 'session_id' to construct a file path using 'SESSION_DIR / f"{sid}.json"'. Because the input is not sanitized, an authenticated attacker can provide an absolute path or path traversal sequences (e.g., '../') to escape the intended session directory. This allows the deletion of any writable .json file on the host system that the server process has permissions to modify. The issue is fixed in version 0.50.32 by implementing regex validation for session IDs and enforcing path containment checks.
Affected products
- nesquena Hermes WebUI versions up to (excluding) 0.50.32
Timeline
- 2026-04-14: patched: Fix merged in pull request #412 and released in v0.50.32
- 2026-04-21: disclosed: CVE published to NVD
References
- https://github.com/nesquena/hermes-webui/commit/3cc5839bf303fa6758bfdac538507407a2929655
- https://github.com/nesquena/hermes-webui/pull/409
- https://github.com/nesquena/hermes-webui/pull/412
- https://github.com/nesquena/hermes-webui/releases/tag/v0.50.132
- https://github.com/nesquena/hermes-webui/releases/tag/v0.50.32
- https://www.vulncheck.com/advisories/nesquena-hermes-webui-arbitrary-file-deletion-via-unvalidated-session-id