SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-67918

HIGH · CVSS 7.5 EPSS 1.04% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-17 · Last synced 2026-09-16

CyberRota Analysis

AI-Generated

A directory traversal vulnerability in hermes-studio version 0.6.26 allows remote attackers to access sensitive information through the validatePath function in the api/hermes/download endpoint. Organizations using this version of hermes-studio should prioritize remediation to prevent unauthorized data exposure. Immediate action is recommended for any entity relying on this software to safeguard their sensitive information.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-67918
Severity
HIGH
CVSS
7.5
EPSS
1.04%

Original NVD Description

Directory Traversal vulnerability in hermes-studio v.0.6.26 allows a remote attacker to obtain sensitive information via the validatePath function in api/hermes/download endpoint