CVE-2026-6829

Source
https://cve.org/CVERecord?id=CVE-2026-6829
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-6829.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-6829
Published
2026-04-21T21:09:59.923Z
Modified
2026-08-07T11:31:05.378500048Z
Severity
  • 5.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N CVSS Calculator
Summary
nesquena hermes-webui Arbitrary Workspace Directory Access
Details

nesquena hermes-webui contains a trust-boundary failure vulnerability that allows authenticated attackers to set or change a session workspace to an arbitrary existing directory on disk by manipulating workspace path parameters in endpoints such as /api/session/new, /api/session/update, /api/chat/start, and /api/workspaces/add. Attackers can repoint a session workspace to a directory outside the intended trusted root and then use ordinary file read and write APIs to access or modify files outside the intended workspace boundary within the permissions of the hermes-webui process.

Database specific
{
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "fixed": "PR #416"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/6xxx/CVE-2026-6829.json",
    "cna_assigner": "VulnCheck",
    "cwe_ids": [
        "CWE-22"
    ]
}
References

Affected packages

Git / github.com/nesquena/hermes-webui

Affected ranges

Type
GIT
Repo
https://github.com/nesquena/hermes-webui
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "source": "REFERENCES"
}

Affected versions

v0.*
v0.12
v0.16
v0.16.1
v0.16.2
v0.17.1
v0.17.2
v0.17.3
v0.18
v0.18.1
v0.19
v0.20
v0.21
v0.22
v0.23
v0.24
v0.25
v0.26
v0.27
v0.28
v0.28.1
v0.29
v0.30
v0.30.1
v0.30.2
v0.30.3
v0.30.4
v0.31
v0.31.1
v0.31.2
v0.32
v0.33
v0.34
v0.34.1
v0.34.2
v0.34.3
v0.35
v0.35.1
v0.36
v0.36.1
v0.36.2
v0.36.3
v0.37.0
v0.38.0
v0.38.1
v0.38.2
v0.38.3
v0.38.4
v0.38.5
v0.38.6
v0.39.0
v0.39.1
v0.40.0
v0.40.1
v0.40.2
v0.41.0
v0.42.0
v0.42.1
v0.42.2
v0.43.0
v0.43.1
v0.44.0
v0.44.1
v0.45.0
v0.46.0
v0.47.0
v0.47.1
v0.48.0
v0.48.1
v0.48.2
v0.49.0
v0.49.1
v0.49.2
v0.49.3
v0.49.4
v0.50.0
v0.50.1
v0.50.10
v0.50.11
v0.50.12
v0.50.13
v0.50.14
v0.50.15
v0.50.16
v0.50.17
v0.50.18
v0.50.19
v0.50.2
v0.50.20
v0.50.21
v0.50.22
v0.50.23
v0.50.24
v0.50.25
v0.50.26
v0.50.27
v0.50.28
v0.50.29
v0.50.3
v0.50.30
v0.50.31
v0.50.32
v0.50.33
v0.50.4
v0.50.5
v0.50.6
v0.50.7
v0.50.8
v0.50.9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-6829.json"