High severity7.5NVD Advisory· Published Jun 17, 2026· Updated Jun 18, 2026
CVE-2026-53869
CVE-2026-53869
Description
Hermes Agent before 0.16.0 contains a DNS rebinding vulnerability in WebSocket endpoints that allows remote attackers to bypass Host and Origin validation. FastAPI HTTP middleware does not execute for WebSocket upgrade requests on /api/pty, /api/ws, /api/pub, and /api/events endpoints, enabling attackers to exploit DNS rebinding and inject malicious commands or read terminal output.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
hermes-agentPyPI | < 0.16.0 | 0.16.0 |
Affected products
1- Range: <0.16.0
Patches
Vulnerability mechanics
References
7- github.com/advisories/GHSA-4pqm-j46f-795xghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-53869ghsaADVISORY
- github.com/NousResearch/hermes-agent/commit/d9ec90585cf7616b5972e44cf8d92bb569fc3febnvdWEB
- github.com/NousResearch/hermes-agent/pull/30221nvdWEB
- github.com/NousResearch/hermes-agent/pull/31685nvdWEB
- github.com/NousResearch/hermes-agent/releases/tag/v2026.6.5nvdWEB
- www.vulncheck.com/advisories/hermes-agent-dns-rebinding-bypass-via-websocket-endpointsnvdWEB
News mentions
0No linked articles in our index yet.