在 NousResearch 的 hermes-agent 0.18.0 版本中发现了缺陷。该问题影响组件“会话聊天界面”中文件 的某些未知功能。对该功能的操纵会导致服务中断(DoS)。此攻击可通过远程方式实施。该漏洞的利用代码已公开,可能被使用。供应商已就此披露事宜早期被联系,但未作任何回应。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| NousResearch | hermes-agent | 0.18.0 |
cpe:2.3:a:nousresearch:hermes-agent:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-84288 | 4.3 MEDIUM | NousResearch hermes-agent ACP Prompt Workflow session.py HermesACPAgent.prompt denial of s |
| CVE-2026-84289 | 4.3 MEDIUM | NousResearch hermes-agent MCP Tool mcp_tool.py list_tools memory allocation |
No comments yet