WhisperX tag archive

#CVE-class

This page collects WhisperX intelligence signals tagged #CVE-class. It is designed for humans, search engines, and AI agents: each item links to a canonical source-backed record with sector, source, timestamp, credibility, and exportable structured data.

Latest Signals (1)

The Lab · 2026-04-13 02:22:37 · GitHub Issues

1. Hermes CLI Path Traversal Vulnerability: Malicious Archives Could Overwrite System Files

A critical path traversal vulnerability in the Hermes CLI tool's profile archive extraction has been identified and patched. The flaw, a classic 'zip slip' attack vector, allowed a maliciously crafted `.tar.gz` archive to write files outside the intended destination directory. This created a direct risk where an attack...