
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-22798 is a credential exposure vulnerability in the hermes Python package (an implementation of the HERMES workflow for automated software publication with rich metadata) caused by raw logging of sensitive command-line arguments. Versions 0.8.1 through 0.9.0 are affected; the issue was introduced in commit 7f64f10 and fixed in version 0.9.1. The vulnerability was disclosed on January 12, 2026, by maintainer sdruskat following a report from researcher @thunze. It carries a CVSS v3.1 base score of 5.9 (Moderate) (GitHub Advisory, GHSA).
The root cause is classified as CWE-532 (Insertion of Sensitive Information into Log File). In src/hermes/commands/cli.py, the main() function logs the full argparse.Namespace object — including all -O subcommand options — in plain text via log.debug("Running hermes with the following command line arguments: %s", args). Because hermes subcommands accept arbitrary key-value pairs under the -O flag (e.g., hermes deposit -O invenio_rdm.auth_token SECRET), any secrets passed this way are written verbatim to hermes.log. The fix in commit 90cb86a introduces a mask_options_values() utility that replaces option values with ***REDACTED*** before logging (GHSA, Patch Commit).
Exploitation allows any local user or CI participant with read access to hermes.log to retrieve plaintext API tokens and other secrets passed via the -O argument. The primary risk scenario involves shared-access systems where log files reside on a commonly accessible filesystem, and CI environments where logs are accessible to other group or organization members. A particularly severe scenario noted in the advisory is that a planned CI template change (softwarepub/ci-templates#14) could have automated the upload of log files as CI artifacts, potentially exposing Invenio auth tokens to all CI run viewers. Successful credential theft enables unauthorized access to connected services and potential lateral movement (GHSA).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. The EPSS score is approximately 0.004% (0th percentile), indicating very low probability of near-term exploitation. The vulnerability requires local access to the log file and low privileges, limiting its attack surface. It is not listed in the CISA Known Exploited Vulnerabilities catalog (GitHub Advisory).
hermes from software-metadata.pub).-O argument, such as hermes deposit -O invenio_rdm.auth_token <SECRET_TOKEN>.hermes.log on the shared filesystem or CI artifact storage. On shared systems, this may be in a world-readable or group-readable directory.Running hermes with the following command line arguments: and extract the plaintext token values from the logged argparse.Namespace output.hermes.log containing debug lines with Running hermes with the following command line arguments: that include -O option values in plaintext (e.g., invenio_rdm.auth_token, auth_token, or similar key names followed by token strings).hermes.log files; log entries showing API token strings in debug output from hermes versions 0.8.1–0.9.0.Upgrade hermes to version 0.9.1 or later, which masks all -O option values in log output using the new mask_options_values() utility. After upgrading, review existing hermes.log files from affected versions (0.8.1–0.9.0) for exposed credentials and immediately revoke and rotate any API tokens found. Restrict filesystem permissions on hermes.log to limit read access to authorized users only as an interim measure. There is no configuration-based workaround for the vulnerable versions other than avoiding passing secrets via the -O argument (GHSA, Patch Commit).
The vulnerability was reported by community contributor @thunze and remediated by sdruskat (remediation developer) and zyzzyxdonta (remediation reviewer), reflecting a responsible disclosure process within the open-source project. Coverage has been limited to automated vulnerability tracking feeds and a brief mention on Bluesky social media. No significant broader industry commentary or media coverage has been identified (GHSA).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."