漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Hermes Agent 0.18.2 - 0.21.0 RCE via git core.fsmonitor Config Injection
Vulnerability Description
Hermes Agent 0.18.2 through 0.21.0, fixed in commit f6234d0, contains a remote code execution vulnerability that allows attackers to execute arbitrary OS commands by supplying a malicious repository with a crafted .git/config that sets core.fsmonitor to an attacker-controlled command. When a user opens the malicious repository and sends any message, the agent triggers a git status index refresh which executes the injected command in the user's process context, exposing the full environment including configured provider API keys.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Vulnerability Type
OS命令中使用的特殊元素转义处理不恰当(OS命令注入)
Vulnerability Title
NousResearch Hermes Agent 命令注入漏洞
Vulnerability Description
Nous Research Hermes Agent是Nous Research团队开源的一款具备自我学习循环的AI代理工具。 NousResearch Hermes Agent 0.18.2版本至0.21.0版本存在命令注入漏洞,该漏洞源于恶意仓库中的特制.git/config文件将core.fsmonitor设置为攻击者控制的命令,可能导致攻击者执行任意OS命令,并暴露包括提供商API密钥在内的完整环境信息。
CVSS Information
N/A
Vulnerability Type
N/A