High severity7.3NVD Advisory· Published May 24, 2026· Updated Jul 23, 2026
CVE-2026-9368
CVE-2026-9368
Description
A vulnerability was identified in NousResearch hermes-agent up to 2026.4.16. This impacts the function execute_code of the file tools/code_execution_tool.py of the component Environment Variable Handler. Such manipulation leads to sandbox issue. It is possible to launch the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
hermes-agentPyPI | < 0.11.0 | 0.11.0 |
Affected products
1- Range: <=2026.4.16
Patches
Vulnerability mechanics
References
7- github.com/advisories/GHSA-wm96-9gfh-vvgqghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-9368ghsaADVISORY
- gist.github.com/YLChen-007/43c72d19668421abe8ce10f299323a0anvdWEB
- github.com/NousResearch/hermes-agent/commit/285bb2b9150b93445e5eded9bc897a4001b66e55ghsaWEB
- vuldb.com/submit/812229nvdWEB
- vuldb.com/vuln/365331nvdWEB
- vuldb.com/vuln/365331/ctinvdWEB
News mentions
1- NousResearch Hermes Agent: Nine CVEs Disclosed in a Single Day Spanning Injection, Sandbox, and Auth FlawsVypr Intelligence · May 24, 2026