hermes-webui vulnerability

Hermes WebUI before 0.51.443 contains a broken access control vulnerability in the /api/session endpoint that allows authenticated users to disclose cross-profile session transcripts. Attackers can bypass profile boundary checks by directly querying session IDs belonging to other profiles via GET /api/session?session_id=<foreign_id>&messages=1 to retrieve unauthorized conversation transcripts and metadata.

Published 17 Jun 2026Updated 17 Sep 20266 sources
CVSS 7.1

Record history

Record created from the first normalized source observation.
Metadata and source references refreshed.