Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vvfr-g83f-8qcv

Опубликовано: 22 апр. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 4.8
CVSS3: 3.3

Описание

nesquena hermes-webui contains an environment variable leakage vulnerability where profile switching does not clear environment variables from the previously active profile before loading the next profile. Attackers or users can exploit additive dotenv reload behavior to access provider API keys and other sensitive secrets from one profile context in another profile, breaking expected security isolation between profiles.

nesquena hermes-webui contains an environment variable leakage vulnerability where profile switching does not clear environment variables from the previously active profile before loading the next profile. Attackers or users can exploit additive dotenv reload behavior to access provider API keys and other sensitive secrets from one profile context in another profile, breaking expected security isolation between profiles.

EPSS

Процентиль: 2%
0.00113
Низкий

4.8 Medium

CVSS4

3.3 Low

CVSS3

Дефекты

CWE-459

Связанные уязвимости

CVSS3: 3.3
nvd
4 месяца назад

nesquena hermes-webui contains an environment variable leakage vulnerability where profile switching does not clear environment variables from the previously active profile before loading the next profile. Attackers or users can exploit additive dotenv reload behavior to access provider API keys and other sensitive secrets from one profile context in another profile, breaking expected security isolation between profiles.

EPSS

Процентиль: 2%
0.00113
Низкий

4.8 Medium

CVSS4

3.3 Low

CVSS3

Дефекты

CWE-459