VYPR

Hermes Agent

by NousResearch

Source repositories

CVEs (35)

  • CVE-2026-9352MedMay 24, 2026
    risk 0.34cvss 5.3epss 0.00

    A weakness has been identified in NousResearch hermes-agent up to 2026.4.23. This issue affects the function _make_run_env of the file tools/environments/local.py of the component Messaging Gateway Handler. Executing a manipulation can lead to information disclosure. The attack…

  • CVE-2026-7396MedApr 29, 2026
    risk 0.34cvss 5.3epss 0.00

    A vulnerability was identified in NousResearch hermes-agent 0.8.0. Affected by this issue is some unknown functionality of the file gateway/platforms/wecom.py of the component WeChat Work Platform Adapter. The manipulation leads to path traversal. It is possible to initiate the…

  • CVE-2026-53870MedJun 17, 2026
    risk 0.29cvss 5.5epss 0.00

    Hermes Agent before 0.16.0 creates response_store.db and webhook_subscriptions.json with world-readable permissions (mode 0o644), exposing conversation history and HMAC secrets to local users. Attackers with local filesystem access can read these files directly to obtain…

  • CVE-2026-10222MedJun 1, 2026
    risk 0.29cvss 5.6epss 0.00

    A security flaw has been discovered in NousResearch hermes-agent up to 2026.4.30. Affected by this issue is the function _sanitize_env_lines of the file hermes_cli/config.py. The manipulation results in injection. It is possible to launch the attack remotely. The attack requires…

  • CVE-2026-7113MedApr 27, 2026
    risk 0.29cvss 5.6epss 0.00

    A vulnerability was found in NousResearch hermes-agent 0.8.0. Affected by this issue is some unknown functionality of the file gateway/platforms/webhook.py of the component Webhooks Endpoint. The manipulation of the argument _INSECURE_NO_AUTH results in missing authentication.…

  • CVE-2026-9369MedMay 24, 2026
    risk 0.27cvss 5.3epss 0.00

    A security flaw has been discovered in NousResearch hermes-agent 2026.4.23. Affected is the function _discover_dashboard_plugins of the file hermes_cli/web_server.py of the component CLI web-dashboard Interface. Performing a manipulation of the argument…

  • CVE-2026-7397MedApr 29, 2026
    risk 0.22cvss 4.4epss 0.00

    A security flaw has been discovered in NousResearch hermes-agent 0.8.0. This affects the function _check_sensitive_path of the file tools/file_tools.py. The manipulation results in symlink following. Attacking locally is a requirement. The exploit has been released to the public…

  • CVE-2026-14783MedJul 6, 2026
    risk 0.21cvss 4.3epss 0.00

    A vulnerability was determined in NousResearch hermes-agent 2026.5.29.2. The impacted element is the function skill_view of the file tools/skills_tool.py. Executing a manipulation of the argument Name can lead to path traversal. The attack can be launched remotely. The exploit…

  • CVE-2026-17432MedJul 26, 2026
    risk 0.00cvss 5.0epss 0.00

    A vulnerability was detected in NousResearch hermes-agent 2026.6.5. Affected by this vulnerability is an unknown functionality of the file hermes-agent/plugins/platforms/simplex/adapter.py of the component SimpleX Gateway Authorization. The manipulation of the argument contactId…

  • CVE-2026-15311LowJul 10, 2026
    risk 0.00cvss 3.5epss 0.00

    A vulnerability was identified in NousResearch hermes-agent up to 2026.5.29.2. Affected by this issue is the function MatrixAdapter._markdown_to_html of the file gateway/platforms/matrix.py of the component Matrix Adapter. Such manipulation leads to cross site scripting. The…

  • CVE-2026-14628MedJul 4, 2026
    risk 0.00cvss 5.3epss 0.01

    A vulnerability was detected in NousResearch hermes-agent up to 2026.5.16. This impacts the function extract_media of the file gateway/platforms/base.py of the component Live Webhook Endpoint. Performing a manipulation results in path traversal. The attack may be initiated…

  • CVE-2026-14627MedJul 4, 2026
    risk 0.00cvss 5.6epss 0.00

    A security vulnerability has been detected in NousResearch hermes-agent up to 0.15.2. This affects the function DiscordAdapter._is_allowed_user of the file gateway/platforms/discord.py of the component Discord Platform Integration. Such manipulation leads to improper…

  • CVE-2026-14626MedJul 4, 2026
    risk 0.00cvss 4.3epss 0.00

    A weakness has been identified in NousResearch hermes-agent up to 2026.4.30. The impacted element is the function AIAgent.run_conversation of the file run_agent.py of the component HTTP API. This manipulation of the argument todos causes denial of service. The attack can be…

  • CVE-2026-14625MedJul 4, 2026
    risk 0.00cvss 6.3epss 0.00

    A security flaw has been discovered in NousResearch hermes-agent up to 0.15.2. The affected element is the function shell.exec of the file tui_gateway/server.py. The manipulation results in protection mechanism failure. It is possible to launch the attack remotely. The exploit…

  • CVE-2026-14617LowJul 3, 2026
    risk 0.00cvss 3.1epss 0.00

    A security vulnerability has been detected in NousResearch hermes-agent up to 2026.4.30. Affected is the function GatewayStreamConsumer._filter_and_accumulate of the file gateway/stream_consumer.py of the component Streaming Reasoning Tag Filter. The manipulation leads to…

Page 2 of 2