Impact
Hermes WebUI before version 0.51.788 permits remote attackers to execute arbitrary shell commands through the embedded terminal API without needing credentials. The weakness stems from insufficient authentication mechanisms (CWE-306) and requires four unauthenticated HTTP requests - first to create a session, then to attach a pseudo-terminal, and finally to feed shell commands. Successful exploitation allows the attacker to run commands with the privileges of the server process, leading to full compromise of confidentiality, integrity, and availability.
Affected Systems
Any deployment of the nesquena Hermes WebUI that runs a version older than 0.51.788 is affected. This includes locally installed installations, containerized deployments, and any environments where the open-source Hermes WebUI is provided without the newer security controls introduced in 0.51.788.
Risk and Exploitability
The CVSS score of 9.3 classifies the vulnerability as critical. Although the overall EPSS score is less than 1%, the lack of authentication and the simple four-step request sequence lower the barrier for an attacker with network access. The issue is not listed in CISA's KEV catalog, but until the patch is applied, exposed instances remain at high risk for compromise.
OpenCVE Enrichment