CVE-2026-6830
published 2026-04-21CVE-2026-6830: nesquena hermes-webui contains an environment variable leakage vulnerability where profile switching does not clear environment variables from the previously…
PriorityP412low3.3CVSS 3.1
AVLACLPRLUINSUCLINAN
EPSS
0.11%
1.7th percentile
nesquena hermes-webui contains an environment variable leakage vulnerability where profile switching does not clear environment variables from the previously active profile before loading the next profile. Attackers or users can exploit additive dotenv reload behavior to access provider API keys and other sensitive secrets from one profile context in another profile, breaking expected security isolation between profiles.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| nesquena | hermes-webui | < PR #351 | PR #351 |
CVSS provenance
nvdv3.13.3LOWCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
nvdv4.04.8MEDIUMCVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-vvfr-g83f-8qcv: nesquena hermes-webui contains an environment variable leakage vulnerability where profile switching does not clear environment variables from the pre
ghsa_unreviewed·2026-04-22
CVE-2026-6830 [MEDIUM] CWE-459 GHSA-vvfr-g83f-8qcv: nesquena hermes-webui contains an environment variable leakage vulnerability where profile switching does not clear environment variables from the pre
nesquena hermes-webui contains an environment variable leakage vulnerability where profile switching does not clear environment variables from the previously active profile before loading the next profile. Attackers or users can exploit additive dotenv reload behavior to access provider API keys and other sensitive secrets from one profile context in another profile, breaking expected security isolation between profiles.
Citrix
Citrix Security Bulletin CTX118768
vendor_citrix·CVSS 4.0
CVE-2008-6830 [MEDIUM] Citrix Security Bulletin CTX118768
Citrix Security Bulletin CTX118768
CVE References: CVE-2008-6830, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/nesquena/hermes-webui/commit/88dc8bbe26a6055161d3251b70f5cd3d3c5831b0https://github.com/nesquena/hermes-webui/pull/351https://github.com/nesquena/hermes-webui/releases/tag/v0.50.12https://github.com/nesquena/hermes-webui/releases/tag/v0.50.132https://www.vulncheck.com/advisories/nesquena-hermes-webui-environment-variable-credential-leakage-via-profile-switch
2026-04-21
Published