hermes-agent
PyPI7 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting hermes-agentpage 1 of 1
- CVE-2026-10222MEDIUMCVSS 5.6EG 5.6✓ Fixed in 0.18.02026-06-01
vulnerable: 0.13.0 ... 0.17.0 (7 versions)
A security flaw has been discovered in NousResearch hermes-agent up to 2026.4.30. Affected by this issue is the function _sanitize_env_lines of the file hermes_cli/config.py. The manipulation results in injection. It is possible to launch …
- CVE-2026-53869HIGHCVSS 7.5EG 7.5✓ Fixed in 0.16.02026-06-17
vulnerable: 0.13.0, 0.14.0, 0.15.0, 0.15.1, 0.15.2
Hermes Agent before 0.16.0 contains a DNS rebinding vulnerability in WebSocket endpoints that allows remote attackers to bypass Host and Origin validation. FastAPI HTTP middleware does not execute for WebSocket upgrade requests on /api/pty…
- CVE-2026-53870MEDIUMCVSS 5.5EG 5.5✓ Fixed in 0.16.02026-06-17
vulnerable: 0.13.0, 0.14.0, 0.15.0, 0.15.1, 0.15.2
Hermes Agent before 0.16.0 creates response_store.db and webhook_subscriptions.json with world-readable permissions (mode 0o644), exposing conversation history and HMAC secrets to local users. Attackers with local filesystem access can rea…
- CVE-2026-9353HIGHCVSS 7.3EG 7.3✓ Fixed in 0.15.02026-05-24
vulnerable: 0.13.0, 0.14.0
A security vulnerability has been detected in NousResearch hermes-agent up to 2026.4.23. Impacted is an unknown function of the file agent/skills_guard.py of the component Skills Guard Multi-Word Prompt Handler. The manipulation of the arg…
- CVE-2026-9366HIGHCVSS 7.3EG 7.3✓ Fixed in 0.15.02026-05-24
vulnerable: 0.13.0, 0.14.0
A vulnerability was found in NousResearch hermes-agent 2026.4.23. The impacted element is the function _scan_context_content of the file agent/prompt_builder.py. The manipulation results in injection. The attack may be performed from remot…
- CVE-2026-9368HIGHCVSS 7.3EG 7.3✓ Fixed in 0.11.02026-05-24
A vulnerability was identified in NousResearch hermes-agent up to 2026.4.16. This impacts the function execute_code of the file tools/code_execution_tool.py of the component Environment Variable Handler. Such manipulation leads to sandbox …
- CVE-2026-9369MEDIUMCVSS 5.3EG 5.3✓ Fixed in 0.15.02026-05-24
vulnerable: 0.13.0, 0.14.0
A security flaw has been discovered in NousResearch hermes-agent 2026.4.23. Affected is the function _discover_dashboard_plugins of the file hermes_cli/web_server.py of the component CLI web-dashboard Interface. Performing a manipulation o…
Check whether hermes-agent is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for hermes-agent CVEs against the assets you own.
Start Free Scan →