Workspace Boundary Bypass in Hermes WebUI Affects Network Security
CVE-2026-49957

6.3MEDIUM

Key Information:

Vendor

Nesquena

Vendor
CVE Published:
9 June 2026

What is CVE-2026-49957?

Hermes WebUI, prior to version 0.51.296, is subject to a workspace boundary bypass vulnerability. This flaw allows authenticated attackers to exploit the workspace resolution logic in the SSH/remote terminal profile, leading to potential unauthorized access to sensitive system files. By manipulating the remote terminal working directory to point to sensitive system paths like /etc, attackers can bypass checks that are meant to restrict access. This oversight stems from an early return in the path validation process, enabling attackers to read local system files without triggering security guards.

Affected Version(s)

hermes-webui 0

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Chia Min Jun Lennon
.