All intelligence
// vulnerability record
cached · NVD via COSMOS syncCVE-2026-67918
NONEpublished 2026-08-17 22:17 UTC · 11 hours ago
CVSS / 10
// description
Directory Traversal vulnerability in hermes-studio v.0.6.26 allows a remote attacker to obtain sensitive information via the validatePath function in api/hermes/download endpoint