Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-jm5j-jfrm-hm23 | hermes's raw options logging may disclose secrets passed in via subcommand options argument |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 14 Jan 2026 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Softwarepub
Softwarepub hermes |
|
| Vendors & Products |
Softwarepub
Softwarepub hermes |
Tue, 13 Jan 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 12 Jan 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | hermes is an implementation of the HERMES workflow to automatize software publication with rich metadata. From 0.8.1 to before 0.9.1, hermes subcommands take arbitrary options under the -O argument. These have been logged in raw form. If users provide sensitive data such as API tokens (e.g., via hermes deposit -O invenio_rdm.auth_token SECRET), these are written to the log file in plain text, making them available to whoever can access the log file. This vulnerability is fixed in 0.9.1. | |
| Title | hermes's raw options logging may disclose secrets passed in via subcommand options argument | |
| Weaknesses | CWE-532 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-01-13T19:08:22.846Z
Reserved: 2026-01-09T22:50:10.287Z
Link: CVE-2026-22798
Updated: 2026-01-13T14:14:28.068Z
Status : Awaiting Analysis
Published: 2026-01-12T22:16:08.780
Modified: 2026-01-13T14:03:18.990
Link: CVE-2026-22798
No data.
OpenCVE Enrichment
Updated: 2026-01-14T11:09:30Z
Github GHSA