Multiple vulnerabilities in NousResearch hermes-agent
Six vulnerabilities were discovered in NousResearch hermes-agent versions up to 0.18.2, including denial of service, authorization bypass, uncontrolled memory allocation, and server-side request forgery. The vendor did not respond to early disclosure attempts.
Disclosed 1 September 2026 · Record updated 13 September 2026
Impact
Multiple remote exploitable vulnerabilities affecting session management, authentication, memory allocation, and request handling in hermes-agent
Our coverage
No articles linked to this incident yet.
Sources
- github.comhttps://github.com/advisories/GHSA-fvfr-42vv-wp2g
- github.comhttps://github.com/advisories/GHSA-mqg2-c725-2vx3
- github.comhttps://github.com/advisories/GHSA-4pg4-vjj9-4j5w
- github.comhttps://github.com/advisories/GHSA-47g2-35xp-x46h
- github.comhttps://github.com/advisories/GHSA-prhp-jh7c-82qx
- github.comhttps://github.com/advisories/GHSA-hgjg-mwp2-fvgj
