PT-2026-50518 · Unknown · Hermes-Agent

·

CVE-2026-53869

·

Published

2026-06-17

·

Updated

2026-07-13

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Hermes Agent versions prior to 0.16.0
Description A DNS rebinding issue in WebSocket endpoints allows remote attackers to bypass Host and Origin validation. This occurs because FastAPI HTTP middleware does not execute for WebSocket upgrade requests on the ' /api/pty', '/api/ws', '/api/pub', and '/api/events' endpoints. DNS rebinding is a technique where a malicious website tricks a browser into sending requests to a local or internal server by manipulating DNS records. This flaw enables attackers to inject malicious commands or read terminal output.
Recommendations Update to version 0.16.0 or later.

Exploit

Fix

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-53869
GHSA-4PQM-J46F-795X
PYSEC-2026-2510

Affected Products

Hermes-Agent