Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

hermes-agent — Vulnerabilities & Security Advisories 35

All 35 CVE vulnerabilities found in hermes-agent, with AI-generated Chinese analysis, references, and POCs.

This page catalogs Common Weakness Enumeration (CWE) vulnerabilities associated with the hermes-agent software product. It aggregates security data to provide a comprehensive view of the weaknesses affecting this specific agent-based system. The content on this page collects reported vulnerabilities that impact the hermes-agent, focusing on the structural and logical flaws that could be exploited by attackers. The data covers a broad historical time range, capturing issues from their initial discovery through to their resolution or ongoing status. This ensures that users can access both legacy and recent security findings without needing to consult multiple disparate sources. By centralizing this information, the page serves as a critical resource for security analysts and system administrators who need to understand the specific risk landscape for hermes-agent. Readers can utilize this resource to track vendor advisories related to hermes-agent updates and patches. You can also deepen your understanding of specific weakness classes by seeing how they manifest within this particular product environment. Furthermore, the page allows you to look up the product's vulnerability history, providing context on how security issues have evolved over time. This structured approach helps in assessing the overall security posture and prioritizing remediation efforts effectively. Whether you are auditing the system or investigating a specific incident, this aggregation offers a clear, factual baseline for decision-making without unnecessary noise.

Vendor: NousResearch

CVE IDTitleCVSSSeverityPublished
CVE-2026-18993 NousResearch hermes-agent Memory Toolset model_tools.py access control CWE-284 6.3 Medium2026-08-06
CVE-2026-18976 NousResearch hermes-agent disabled_toolsets agent_init.py get_tool_definitions privileges assignment CWE-266 6.3 Medium2026-08-06
CVE-2026-18775 NousResearch hermes-agent Browser Tooling browser_tool.py browser_snapshot server-side request forgery CWE-918 6.3 Medium2026-08-04
CVE-2026-18774 NousResearch hermes-agent xAI Image Generation Provider image_gen_provider.py save_url_image server-side request forgery CWE-918 6.3 Medium2026-08-04
CVE-2026-18773 NousResearch hermes-agent Quick run.py _check_slash_access authorization CWE-863 6.3 Medium2026-08-04
CVE-2026-17432 NousResearch hermes-agent SimpleX Gateway Authorization adapter.py access control CWE-284 5.0 Medium2026-07-26
CVE-2026-15311 NousResearch hermes-agent Matrix Adapter matrix.py MatrixAdapter._markdown_to_html cross site scripting CWE-79 3.5 Low2026-07-09
CVE-2026-14783 NousResearch hermes-agent skills_tool.py skill_view path traversal CWE-22 4.3 Medium2026-07-05
CVE-2026-14628 NousResearch hermes-agent Live Webhook Endpoint base.py extract_media path traversal CWE-22 5.3 Medium2026-07-04
CVE-2026-14627 NousResearch hermes-agent Discord Platform Integration discord.py DiscordAdapter._is_allowed_user improper authentication CWE-287 5.6 Medium2026-07-04
CVE-2026-14626 NousResearch hermes-agent HTTP API run_agent.py AIAgent.run_conversation denial of service CWE-404 4.3 Medium2026-07-04
CVE-2026-14625 NousResearch hermes-agent server.py shell.exec protection mechanism CWE-693 6.3 Medium2026-07-04
CVE-2026-14617 NousResearch hermes-agent Streaming Reasoning Tag Filter stream_consumer.py GatewayStreamConsumer._filter_and_accumulate case sensitivity CWE-178 3.1 Low2026-07-03
CVE-2026-53870 Hermes Agent < 0.16.0 - Sensitive File Permission Vulnerability in Store Files CWE-276 5.5 Medium2026-06-17
CVE-2026-53869 Hermes Agent < 0.16.0 - DNS Rebinding Bypass via WebSocket Endpoints CWE-306 7.5 High2026-06-17
CVE-2026-11461 NousResearch hermes-agent resume Endpoint hermes_state.py resolve_session_by_title authorization CWE-639 6.3 Medium2026-06-07
CVE-2026-10548 NousResearch hermes-agent Credential Pool Synchronization credential_pool.py _sync_anthropic_entry_from_credentials_file improper authentication CWE-287 5.3 Medium2026-06-02
CVE-2026-10224 NousResearch hermes-agent Webhook Endpoint feishu.py _handle_webhook_request resource consumption CWE-400 5.3 Medium2026-06-01
CVE-2026-10223 NousResearch hermes-agent memory_tool.py _scan_memory_content injection CWE-74 6.3 Medium2026-06-01
CVE-2026-10222 NousResearch hermes-agent config.py _sanitize_env_lines injection CWE-74 5.6 Medium2026-06-01
CVE-2026-10221 NousResearch hermes-agent run_agent.py _compress_context injection CWE-74 7.3 High2026-06-01
CVE-2026-10220 NousResearch hermes-agent skills_tool.py skill_view injection CWE-74 7.3 High2026-06-01
CVE-2026-9369 NousResearch hermes-agent CLI web-dashboard web_server.py _discover_dashboard_plugins comparison CWE-697 5.3 Medium2026-05-24
CVE-2026-9368 NousResearch hermes-agent Environment Variable code_execution_tool.py execute_code sandbox CWE-265 7.3 High2026-05-24
CVE-2026-9367 NousResearch hermes-agent terminal_tool approval.py detect_dangerous_command os command injection CWE-78 7.3 High2026-05-24
CVE-2026-9366 NousResearch hermes-agent prompt_builder.py _scan_context_content injection CWE-74 7.3 High2026-05-24
CVE-2026-9354 NousResearch hermes-agent Slack Agent/Mattermost Agent escape output CWE-116 6.5 Medium2026-05-24
CVE-2026-9353 NousResearch hermes-agent Skills Guard Multi-Word Prompt skills_guard.py injection CWE-74 7.3 High2026-05-24
CVE-2026-9352 NousResearch hermes-agent Messaging Gateway local.py _make_run_env information disclosure CWE-200 5.3 Medium2026-05-24
CVE-2026-9351 NousResearch hermes-agent read_file Tool file_tools.py _is_blocked_device path traversal CWE-22 6.5 Medium2026-05-24

All 35 known CVE vulnerabilities affecting hermes-agent with full Chinese analysis, references, and POCs where available.