Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

Hermes Agent RCE via malicious .git/config

Hermes Agent versions 0.18.2 through 0.21.0 contain a remote code execution vulnerability allowing attackers to execute arbitrary OS commands by supplying a malicious repository with a crafted .git/config file that sets core.fsmonitor to an attacker-controlled command.

Disclosed 3 September 2026 · Record updated 13 September 2026

Impact

Attackers can execute arbitrary OS commands in the user's process context, potentially exposing configured provider API keys and other environment variables.

Our coverage

No articles linked to this incident yet.

Sources

  1. github.comhttps://github.com/advisories/GHSA-cc88-9pxf-j2wv