CVE-2026-9353: Prompt injection flaw in NousResearch hermes-agent Skills Guard
A publicly disclosed vulnerability (CVE-2026-9353) in NousResearch hermes-agent up to version 2026.4.23 allows remote injection via manipulation of the THREAT_PATTERNS argument in the Skills Guard Multi-Word Prompt Handler (agent/skills_guard.py). The exploit has been published and the vendor did not respond to disclosure attempts.
Disclosed 24 May 2026 · Record updated 13 September 2026
Impact
Remotely exploitable injection in the agent's prompt threat-pattern guard; exploit code publicly disclosed and no vendor response.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-9353
