CyberRota Analysis
AI-GeneratedA directory traversal vulnerability in hermes-studio version 0.6.26 allows remote attackers to access sensitive information through the validatePath function in the api/hermes/download endpoint. Organizations using this version of hermes-studio should prioritize remediation to prevent unauthorized data exposure. Immediate action is recommended for any entity relying on this software to safeguard their sensitive information.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Directory Traversal vulnerability in hermes-studio v.0.6.26 allows a remote attacker to obtain sensitive information via the validatePath function in api/hermes/download endpoint