PT-2026-42926 · Nousresearch · Hermes-Agent

Eric-I

·

Published

2026-05-24

·

Updated

2026-05-24

·

CVE-2026-9366

CVSS v3.1

7.3

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
A vulnerability was found in NousResearch hermes-agent 2026.4.23. The impacted element is the function scan context content of the file agent/prompt builder.py. The manipulation results in injection. The attack may be performed from remote. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

Exploit

Special Elements Injection

Improper Neutralization

Weakness Enumeration

Related Identifiers

CVE-2026-9366

Affected Products

Hermes-Agent