Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
NousResearch hermes-agent Batch Runner approval.py check_all_command_guards authorization
Vulnerability Description
A vulnerability was identified in NousResearch hermes-agent up to 2026.4.16. This affects the function check_all_command_guards of the file tools/approval.py of the component Batch Runner. Such manipulation leads to missing authorization. The attack can be launched remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Vulnerability Type
授权机制缺失
Vulnerability Title
Hermes Agent 安全漏洞
Vulnerability Description
Hermes Agent是Nous Research开源的一款具备自我学习循环的AI代理工具。 Hermes Agent 2026.4.16及之前版本存在安全漏洞,该漏洞源于Batch Runner组件文件tools/approval.py中函数check_all_command_guards,可能导致缺少授权。
CVSS Information
N/A
Vulnerability Type
N/A