CVE-2026-18773

Summary

A vulnerability was detected in NousResearch hermes-agent up to 2026.6.5. Affected by this issue is the function _check_slash_access of the file gateway/run.py of the component Quick Command Handler. The manipulation results in incorrect authorization. The attack can be launched remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Affected Software

VendorProductVersion RangeStatus
NousResearchhermes-agent2026.6.0affected
NousResearchhermes-agent2026.6.1affected
NousResearchhermes-agent2026.6.2affected
NousResearchhermes-agent2026.6.3affected
NousResearchhermes-agent2026.6.4affected
NousResearchhermes-agent2026.6.5affected

Weaknesses

  • CWE-863: Incorrect Authorization
  • CWE-285: Improper Authorization

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: poc
    • Automatable: no
    • Technical Impact: partial

References