{"id":"CVE-2026-22798","summary":"hermes's raw options logging may disclose secrets passed in via subcommand options argument","details":"hermes is an implementation of the HERMES workflow to automatize software publication with rich metadata. From 0.8.1 to before 0.9.1, hermes subcommands take arbitrary options under the -O argument. These have been logged in raw form. If users provide sensitive data such as API tokens (e.g., via hermes deposit -O invenio_rdm.auth_token SECRET), these are written to the log file in plain text, making them available to whoever can access the log file. This vulnerability is fixed in 0.9.1.","aliases":["GHSA-jm5j-jfrm-hm23","PYSEC-2026-1449"],"modified":"2026-08-12T03:51:13.727135250Z","published":"2026-01-12T22:00:30.175Z","database_specific":{"cwe_ids":["CWE-532"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/22xxx/CVE-2026-22798.json","cna_assigner":"GitHub_M"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/22xxx/CVE-2026-22798.json"},{"type":"ADVISORY","url":"https://github.com/softwarepub/hermes/security/advisories/GHSA-jm5j-jfrm-hm23"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-22798"},{"type":"FIX","url":"https://github.com/softwarepub/hermes/commit/7f64f102e916c76dc44404b77ab2a80f5a4e59b1"},{"type":"FIX","url":"https://github.com/softwarepub/hermes/commit/90cb86acd026e7841f2539ae7a1b284a7f263514"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/softwarepub/hermes","events":[{"introduced":"0e73ac96f8739d67d1d978b2ba9797f5e5b51f49"},{"fixed":"890e081cfcbdc321901235098f5e85cbd9a2af5c"},{"fixed":"7f64f102e916c76dc44404b77ab2a80f5a4e59b1"},{"fixed":"90cb86acd026e7841f2539ae7a1b284a7f263514"}],"database_specific":{"cpe":"cpe:2.3:a:software-metadata.pub:hermes:*:*:*:*:*:python:*:*","extracted_events":[{"introduced":"0.8.1"},{"fixed":"0.9.1"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["v0.8.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-22798.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:N"}]}