Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Hermes Agent 0.18.2 - 0.21.0 RCE via git core.fsmonitor Config Injection
Vulnerability Description
Hermes Agent 0.18.2 through 0.21.0, fixed in commit f6234d0, contains a remote code execution vulnerability that allows attackers to execute arbitrary OS commands by supplying a malicious repository with a crafted .git/config that sets core.fsmonitor to an attacker-controlled command. When a user opens the malicious repository and sends any message, the agent triggers a git status index refresh which executes the injected command in the user's process context, exposing the full environment including configured provider API keys.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Vulnerability Type
OS命令中使用的特殊元素转义处理不恰当(OS命令注入)
Vulnerability Title
NousResearch Hermes Agent 命令注入漏洞
Vulnerability Description
Nous Research Hermes Agent是Nous Research团队开源的一款具备自我学习循环的AI代理工具。 NousResearch Hermes Agent 0.18.2版本至0.21.0版本存在命令注入漏洞,该漏洞源于恶意仓库中的特制.git/config文件将core.fsmonitor设置为攻击者控制的命令,可能导致攻击者执行任意OS命令,并暴露包括提供商API密钥在内的完整环境信息。
CVSS Information
N/A
Vulnerability Type
N/A