Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
NousResearch hermes-agent terminal_tool approval.py detect_dangerous_command os command injection
Vulnerability Description
A vulnerability was determined in NousResearch hermes-agent up to 5157f5427f19488b31c6fdebbacd15d798ce7f63. This affects the function detect_dangerous_command of the file tools/approval.py of the component terminal_tool. This manipulation causes os command injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Vulnerability Type
OS命令中使用的特殊元素转义处理不恰当(OS命令注入)
Vulnerability Title
Hermes Agent 操作系统命令注入漏洞
Vulnerability Description
Hermes Agent是Nous Research开源的一款具备自我学习循环的AI代理工具。 Hermes Agent 5157f5427f19488b31c6fdebbacd15d798ce7f63及之前版本存在操作系统命令注入漏洞,该漏洞源于组件terminal_tool中文件tools/approval.py的函数detect_dangerous_command操作不当,可能导致OS命令注入。
CVSS Information
N/A
Vulnerability Type
N/A