Trust-Boundary Failure in Nesquena Hermes-WebUI
CVE-2026-6829
5.3MEDIUM
What is CVE-2026-6829?
The Nesquena Hermes-WebUI suffers from a trust-boundary failure that could allow authenticated attackers to manipulate session workspace paths. This vulnerability enables them to redirect a session workspace to arbitrary directories on disk by exploiting parameters in key API endpoints such as /api/session/new, /api/session/update, /api/chat/start, and /api/workspaces/add. Consequently, this flaw could give attackers the ability to access or alter files outside the designated workspace boundaries, leveraging standard file read and write APIs within the permissions of the hermes-webui process.
Affected Version(s)
hermes-webui 0
