PT-2026-47189 · Nousresearch · Hermes-Agent

Eric-B

·

Published

2026-06-07

·

Updated

2026-06-07

·

CVE-2026-11461

CVSS v3.1

6.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
A vulnerability has been found in NousResearch hermes-agent up to 0.12.0. This affects the function resolve session by title of the file hermes state.py of the component resume Endpoint. Such manipulation of the argument Title leads to authorization bypass. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Exploit

Fix

IDOR

Improper Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-11461

Affected Products

Hermes-Agent