High severityNVD Advisory· Published Jun 17, 2026
Hermes Agent < 0.16.0 - DNS Rebinding Bypass via WebSocket Endpoints
CVE-2026-53869
Description
Hermes Agent before 0.16.0 contains a DNS rebinding vulnerability in WebSocket endpoints that allows remote attackers to bypass Host and Origin validation. FastAPI HTTP middleware does not execute for WebSocket upgrade requests on /api/pty, /api/ws, /api/pub, and /api/events endpoints, enabling attackers to exploit DNS rebinding and inject malicious commands or read terminal output.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
hermes-agentPyPI | < 0.16.0 | 0.16.0 |
Affected products
1- Range: <0.16.0
Patches
Vulnerability mechanics
References
7- github.com/NousResearch/hermes-agent/commit/d9ec90585cf7616b5972e44cf8d92bb569fc3febghsapatchWEB
- github.com/advisories/GHSA-4pqm-j46f-795xghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-53869ghsaADVISORY
- www.vulncheck.com/advisories/hermes-agent-dns-rebinding-bypass-via-websocket-endpointsghsathird-party-advisoryWEB
- github.com/NousResearch/hermes-agent/pull/30221ghsaissue-trackingWEB
- github.com/NousResearch/hermes-agent/pull/31685ghsaissue-trackingWEB
- github.com/NousResearch/hermes-agent/releases/tag/v2026.6.5ghsarelease-notesWEB
News mentions
0No linked articles in our index yet.