CVE-2026-6830: CWE-668: Exposure of Resource to Wrong Sphere in nesquena hermes-webui
nesquena hermes-webui contains an environment variable leakage vulnerability where profile switching does not clear environment variables from the previously active profile before loading the next profile. Attackers or users can exploit additive dotenv reload behavior to access provider API keys and other sensitive secrets from one profile context in another profile, breaking expected security isolation between profiles.
AI Analysis
Technical Summary
CVE-2026-6830 describes an environment variable leakage vulnerability in nesquena hermes-webui (version 0). When switching profiles, the application fails to clear environment variables from the previous profile before loading the next one. This additive dotenv reload behavior enables attackers or users to access sensitive secrets, including provider API keys, from one profile context while operating in another. This breaks the intended security isolation between profiles and exposes sensitive resources to an unintended sphere. The vulnerability has a CVSS 4.0 score of 4.8, reflecting a medium impact with local attack vector and low complexity.
Potential Impact
The vulnerability allows unauthorized access to environment variables containing sensitive information such as API keys from one profile while operating in another profile context. This breaks security isolation between profiles and could lead to unauthorized use of credentials or data leakage within the application environment. The impact is limited by the requirement for local access and low privileges, and no known exploits are reported in the wild.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, users should avoid switching profiles in a way that relies on environment variable isolation or manually clear environment variables between profile switches if possible. Monitor vendor communications for updates on remediation.
CVE-2026-6830: CWE-668: Exposure of Resource to Wrong Sphere in nesquena hermes-webui
Description
nesquena hermes-webui contains an environment variable leakage vulnerability where profile switching does not clear environment variables from the previously active profile before loading the next profile. Attackers or users can exploit additive dotenv reload behavior to access provider API keys and other sensitive secrets from one profile context in another profile, breaking expected security isolation between profiles.
CVSS v4.0
Score 4.8medium
Affected software
pkg:github/nesquena/hermes-webuiRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-6830 describes an environment variable leakage vulnerability in nesquena hermes-webui (version 0). When switching profiles, the application fails to clear environment variables from the previous profile before loading the next one. This additive dotenv reload behavior enables attackers or users to access sensitive secrets, including provider API keys, from one profile context while operating in another. This breaks the intended security isolation between profiles and exposes sensitive resources to an unintended sphere. The vulnerability has a CVSS 4.0 score of 4.8, reflecting a medium impact with local attack vector and low complexity.
Potential Impact
The vulnerability allows unauthorized access to environment variables containing sensitive information such as API keys from one profile while operating in another profile context. This breaks security isolation between profiles and could lead to unauthorized use of credentials or data leakage within the application environment. The impact is limited by the requirement for local access and low privileges, and no known exploits are reported in the wild.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, users should avoid switching profiles in a way that relies on environment variable isolation or manually clear environment variables between profile switches if possible. Monitor vendor communications for updates on remediation.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-04-21T21:22:31.635Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 69e7f01d19fe3cd2cdfcab55
Added to database: 04/21/2026, 21:46:05 UTC
Last enriched: 07/15/2026, 09:57:33 UTC
Last updated: 07/31/2026, 19:23:00 UTC
Views: 151
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.