hermes-agent
PyPI10 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting hermes-agentpage 1 of 1
- CVE-2026-10221HIGHCVSS 7.3EG 7.32026-06-01
vulnerable: 0.13.0 ... 0.19.0 (11 versions)
A vulnerability was identified in NousResearch hermes-agent up to 0.12.0. Affected by this vulnerability is the function _compress_context of the file run_agent.py. The manipulation leads to injection. It is possible to initiate the attack…
- CVE-2026-10222MEDIUMCVSS 5.6EG 5.6✓ Fixed in 0.18.02026-06-01
vulnerable: 0.13.0 ... 0.17.0 (7 versions)
A security flaw has been discovered in NousResearch hermes-agent up to 2026.4.30. Affected by this issue is the function _sanitize_env_lines of the file hermes_cli/config.py. The manipulation results in injection. It is possible to launch …
- CVE-2026-10223MEDIUMCVSS 6.3EG 6.3✓ Fixed in 0.15.02026-06-01
vulnerable: 0.13.0, 0.14.0
A weakness has been identified in NousResearch hermes-agent up to 2026.4.30. This affects the function _scan_memory_content of the file tools/memory_tool.py. This manipulation causes injection. The attack can be initiated remotely. The exp…
- CVE-2026-10224MEDIUMCVSS 5.3EG 5.32026-06-01
vulnerable: 0.13.0 ... 0.19.0 (11 versions)
A security vulnerability has been detected in NousResearch hermes-agent up to 2026.4.30. This vulnerability affects the function _handle_webhook_request of the file gateway/platforms/feishu.py of the component Webhook Endpoint. Such manipu…
- CVE-2026-53869HIGHCVSS 7.5EG 7.5✓ Fixed in 0.16.02026-06-17
vulnerable: 0.13.0, 0.14.0, 0.15.0, 0.15.1, 0.15.2
Hermes Agent before 0.16.0 contains a DNS rebinding vulnerability in WebSocket endpoints that allows remote attackers to bypass Host and Origin validation. FastAPI HTTP middleware does not execute for WebSocket upgrade requests on /api/pty…
- CVE-2026-53870MEDIUMCVSS 5.5EG 5.5✓ Fixed in 0.16.02026-06-17
vulnerable: 0.13.0, 0.14.0, 0.15.0, 0.15.1, 0.15.2
Hermes Agent before 0.16.0 creates response_store.db and webhook_subscriptions.json with world-readable permissions (mode 0o644), exposing conversation history and HMAC secrets to local users. Attackers with local filesystem access can rea…
- CVE-2026-9353HIGHCVSS 7.3EG 7.3✓ Fixed in 0.15.02026-05-24
vulnerable: 0.13.0, 0.14.0
A security vulnerability has been detected in NousResearch hermes-agent up to 2026.4.23. Impacted is an unknown function of the file agent/skills_guard.py of the component Skills Guard Multi-Word Prompt Handler. The manipulation of the arg…
- CVE-2026-9366HIGHCVSS 7.3EG 7.3✓ Fixed in 0.15.02026-05-24
vulnerable: 0.13.0, 0.14.0
A vulnerability was found in NousResearch hermes-agent 2026.4.23. The impacted element is the function _scan_context_content of the file agent/prompt_builder.py. The manipulation results in injection. The attack may be performed from remot…
- CVE-2026-9368HIGHCVSS 7.3EG 7.3✓ Fixed in 0.11.02026-05-24
A vulnerability was identified in NousResearch hermes-agent up to 2026.4.16. This impacts the function execute_code of the file tools/code_execution_tool.py of the component Environment Variable Handler. Such manipulation leads to sandbox …
- CVE-2026-9369MEDIUMCVSS 5.3EG 5.3✓ Fixed in 0.15.02026-05-24
vulnerable: 0.13.0, 0.14.0
A security flaw has been discovered in NousResearch hermes-agent 2026.4.23. Affected is the function _discover_dashboard_plugins of the file hermes_cli/web_server.py of the component CLI web-dashboard Interface. Performing a manipulation o…
Check whether hermes-agent is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for hermes-agent CVEs against the assets you own.
Start Free Scan →