Hermes Agent 在 0.16.0 至 0.17.0 之前的版本中存在一个路径限制不当(improper path restriction)漏洞,允许能够影响被摄取消息内容的攻击者通过绕过排除 文件的敏感路径保护机制,覆盖凭证存储(credential store)。 攻击者可以构造恶意消息,引导 Agent 的文件写入工具直接覆盖凭证存储,而不会触发任何基于路径的保护机制,从而可能导致凭证被篡改或未授权的访问。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| NousResearch | hermes-agent | 0.16.0< 0.17.0 |
affected |
2026.6.5< 2026.6.19 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| NousResearch | hermes-agent | 0.16.0 ~ 0.17.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet