CVE 5.9 MEDIUM

hermes’s raw options logging may disclose secrets passed in via subcommand options argument_CVE-2026-22798

5.9 / 10
MEDIUM
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:N

Description

hermes is an implementation of the HERMES workflow to automatize software publication with rich metadata. From 0.8.1 to before 0.9.1, hermes subcommands take arbitrary options under the -O argument. These have been logged in raw form. If users provide sensitive data such as API tokens (e.g., via hermes deposit -O invenio_rdm.auth_token SECRET), these are written to the log file in plain text, making them available to whoever can access the log file. This vulnerability is fixed in 0.9.1.

Basic Information

ID CVE-2026-22798
Source GitHub_M
Published Jan 12, 2026 at 22:00

Affected Product

Vendor softwarepub
Product hermes
Version >= 0.8.1, < 0.9.1
Affected Versions softwarepub hermes >= 0.8.1, < 0.9.1

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.