Path Traversal Vulnerability in Hermes WebUI Affects Sensitive Data Security
CVE-2026-11322
7.1HIGH
What is CVE-2026-11322?
Hermes WebUI versions prior to v0.51.221 are susceptible to a path traversal vulnerability stemming from improper handling of symbolic links. This flaw permits attackers to access files and directories beyond the intended workspace root by exploiting the file and listing APIs. As a result, attackers may gain unauthorized access to sensitive data stored on the server, including SSH keys, cloud credentials, and application tokens, thereby compromising the security of the affected systems.
Affected Version(s)
Hermes WebUI 0 < 0.51.221
