Signal is active with 3 mentions in latest observed window
Immediate actions
Patch affected systems immediately
Recommended action window: Monitor and triage in normal cycle
NVD description
Hermes WebUI before 0.51.307 contains an authentication bypass vulnerability that allows unauthenticated remote attackers to circumvent local-origin IP restrictions on onboarding endpoints by supplying a spoofed X-Forwarded-For header with a loopback address. Attackers can exploit this bypass to perform server-side request forgery against internal services including cloud metadata endpoints, overwrite LLM provider configuration and API keys with attacker-controlled values, or initiate OAuth device-code flows to obtain persistent access tokens stored in auth.json.
🚨 CVE-2026-58122 — CVSS 9.1/10
█████████░
Hermes WebUI before 0.51.307 contains an authentication bypass vulnerability that allows unauthenticated remote...
Severity: CRITICAL
Patch now.
#cybersecurity#CVE https://t.co/9QMfnFicJD
Post summary
The tweet alerts about a critical authentication bypass in Hermes WebUI with a CVSS of 9.1, urges immediate patching, and does not provide a PoC or exploit details.
🚨Critical - Hermes WebUI Unauthenticated RCE via Terminal API (CVE-2026-58123)
Hermes WebUI exposes its embedded terminal API endpoints with no authentication. A remote unauthenticated attacker can, in four sequential HTTP requests, create a session, attach a PTY shell, and write arbitrary commands through the terminal input endpoint - achieving full shell command execution as the server process user.
This is a direct, high-reliability unauth RCE: a browser-based shell reachable over HTTP without credentials. It's the second critical Hermes WebUI flaw from this cycle alongside the X-Forwarded-For auth bypass (CVE-2026-58122).
👉Upgrade Hermes WebUI to 0.51.788.
Post summary
Hermes WebUI has a critical unauthenticated RCE via its terminal API; upgrading to version 0.51.788 is the advised fix.
🚨Critical - Hermes WebUI Auth Bypass via X-Forwarded-For Spoofing (CVE-2026-58122)
Hermes WebUI restricts its onboarding endpoints to local-origin IPs, but the check trusts the client-supplied X-Forwarded-For header. A remote unauthenticated attacker can send a spoofed X-Forwarded-For with a loopback address (127.0.0.1) to appear local and bypass the restriction.
With that bypass, an attacker can perform SSRF against internal services and cloud metadata endpoints, overwrite LLM provider configuration and API keys with attacker-controlled values, or start OAuth device-code flows to grab persistent access tokens stored in auth.json.
👉Upgrade Hermes WebUI to 0.51.307.
Post summary
The advisory discloses an X‑Forwarded‑For spoofing flaw in Hermes WebUI (CVE‑2026‑58122) that permits SSRF, configuration tampering, and token theft, and recommends upgrading to version 0.51.307 for remediation.