Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-6830

Опубликовано: 21 апр. 2026
Источник: nvd
CVSS3: 3.3
EPSS Низкий

Описание

nesquena hermes-webui contains an environment variable leakage vulnerability where profile switching does not clear environment variables from the previously active profile before loading the next profile. Attackers or users can exploit additive dotenv reload behavior to access provider API keys and other sensitive secrets from one profile context in another profile, breaking expected security isolation between profiles.

EPSS

Процентиль: 2%
0.00113
Низкий

3.3 Low

CVSS3

Дефекты

CWE-459

Связанные уязвимости

CVSS3: 3.3
github
4 месяца назад

nesquena hermes-webui contains an environment variable leakage vulnerability where profile switching does not clear environment variables from the previously active profile before loading the next profile. Attackers or users can exploit additive dotenv reload behavior to access provider API keys and other sensitive secrets from one profile context in another profile, breaking expected security isolation between profiles.

EPSS

Процентиль: 2%
0.00113
Низкий

3.3 Low

CVSS3

Дефекты

CWE-459