Nous Research Hermes Agent是Nous Research团队开源的一款具备自我学习循环的AI代理工具。 Nous Research Hermes Agent 0.15.2及之前版本存在授权问题漏洞,该漏洞源于Discord Platform Integration组件的gateway/platforms/discord.py文件中DiscordAdapter._is_allowed_user函数存在身份验证不当问题,可能导致远程攻击。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| NousResearch | hermes-agent | 0.15.0 |
affected |
0.15.1 |
affected | ||
0.15.2 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| NousResearch | hermes-agent | 0.15.0 |
cpe:2.3:a:nousresearch:hermes-agent:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-14625 | 6.3 MEDIUM | NousResearch hermes-agent server.py shell.exec protection mechanism |
| CVE-2026-14628 | 5.3 MEDIUM | NousResearch hermes-agent Live Webhook Endpoint base.py extract_media path traversal |
| CVE-2026-14626 | 4.3 MEDIUM | NousResearch hermes-agent HTTP API run_agent.py AIAgent.run_conversation denial of service |
No comments yet