在 NousResearch 的 hermes-agent(版本 0.18.2 及更早版本)中发现了一个漏洞。该漏洞位于 ACP Prompt 工作流组件中 文件的 函数。对该函数的操纵可导致服务拒绝(DoS)攻击。该攻击可从远程执行。该漏洞的利用方式已向公众披露,并可能被利用。厂商此前已就此事被联系,但未作出任何回应。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| NousResearch | hermes-agent | 0.18.0 |
cpe:2.3:a:nousresearch:hermes-agent:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-84287 | 4.3 MEDIUM | NousResearch hermes-agent Session Chat api_server.py denial of service |
| CVE-2026-84289 | 4.3 MEDIUM | NousResearch hermes-agent MCP Tool mcp_tool.py list_tools memory allocation |
No comments yet