Junglewise Threat Intelligence

CVE-2026-6832: nesquena Hermes WebUI arbitrary file deletion in session API

CVE-2026-6832 · Severity: high · CVSS 8.1 · Published 2026-04-21

Technologies: Nesquena Hermes WebUI. Vendors: Nesquena.

Executive brief

Hermes WebUI, a web interface for managing sessions, contains a security flaw that allows logged-in users to delete arbitrary files on the server. By sending a specially crafted request to the session deletion endpoint, an attacker can bypass intended restrictions and remove critical system or application files. This could lead to data loss, service disruption, or the corruption of application state.

Technical details

An arbitrary file deletion vulnerability exists in Hermes WebUI due to improper validation of the 'session_id' parameter in the '/api/session/delete' endpoint. The application uses the user-provided 'session_id' to construct a file path using 'SESSION_DIR / f"{sid}.json"'. Because the input is not sanitized, an authenticated attacker can provide an absolute path or path traversal sequences (e.g., '../') to escape the intended session directory. This allows the deletion of any writable .json file on the host system that the server process has permissions to modify. The issue is fixed in version 0.50.32 by implementing regex validation for session IDs and enforcing path containment checks.

Affected products

  • nesquena Hermes WebUI versions up to (excluding) 0.50.32

Timeline

  • 2026-04-14: patched: Fix merged in pull request #412 and released in v0.50.32
  • 2026-04-21: disclosed: CVE published to NVD

References

Related threats