CVE-2026-67918: Hermes-studio hermes-studio vulnerability
Published Aug 17, 2026
·Updated
Directory Traversal vulnerability in hermes-studio v.0.6.26 allows a remote attacker to obtain sensitive information via the validatePath function in api/hermes/download endpoint
Affected Software
1 affected component
hermes-studio hermes-studio=0.6.26
Event History
Aug 17, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·10:17 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2026-67918?
CVE-2026-67918 has a risk rating of 52, indicating a moderate severity level.
2
How does CVE-2026-67918 affect hermes-studio?
CVE-2026-67918 allows a remote attacker to exploit a directory traversal vulnerability to access sensitive information.
3
How do I fix CVE-2026-67918?
To mitigate CVE-2026-67918, update hermes-studio to the latest version that addresses this vulnerability.
4
Who is affected by CVE-2026-67918?
Users of hermes-studio version 0.6.26 are vulnerable to CVE-2026-67918.
5
What type of vulnerability is CVE-2026-67918?
CVE-2026-67918 is classified as a directory traversal vulnerability.