PT-2026-42906 · Nousresearch · Hermes-Agent

·

CVE-2026-9350

·

Published

2026-05-24

·

Updated

2026-05-24

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions hermes-agent versions prior to 2026.4.17
Description A flaw in the Batch Runner component of NousResearch hermes-agent allows for remote manipulation. The issue resides in the check all command guards() function within the tools/approval.py file, which can lead to missing authorization.
Recommendations Update to a version later than 2026.4.16. As a temporary workaround, restrict access to the check all command guards() function in the tools/approval.py file to minimize the risk of exploitation.

Exploit

Fix

Missing Authorization

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-9350

Affected Products

Hermes-Agent