All 4 CVE vulnerabilities found in hermes-agent, with AI-generated Chinese analysis, references, and POCs.
Vendor: NousResearch
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-7397 | NousResearch hermes-agent file_tools.py _check_sensitive_path symlink CWE-61 | 4.4 | Medium | 2026-04-29 |
| CVE-2026-7396 | NousResearch hermes-agent WeChat Work Platform Adapter wecom.py path traversal CWE-22 | 5.3 | Medium | 2026-04-29 |
| CVE-2026-7113 | NousResearch hermes-agent Webhooks Endpoint webhook.py missing authentication CWE-306 | 5.6 | Medium | 2026-04-27 |
| CVE-2026-7112 | NousResearch hermes-agent API_SERVER_KEY api_server.py _check_auth improper authentication CWE-287 | 5.6 | Medium | 2026-04-27 |
All 4 known CVE vulnerabilities affecting hermes-agent with full Chinese analysis, references, and POCs where available.