PT-2026-50518 · Nousresearch · Hermes-Agent
Published
2026-06-17
·
Updated
2026-06-17
·
CVE-2026-53869
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Hermes Agent versions prior to 0.16.0
Description
A DNS rebinding issue in WebSocket endpoints allows remote attackers to bypass Host and Origin validation. This occurs because FastAPI HTTP middleware does not execute for WebSocket upgrade requests on the ' /api/pty', '/api/ws', '/api/pub', and '/api/events' endpoints. DNS rebinding is a technique where a malicious website tricks a browser into sending requests to a local or internal server by manipulating DNS records. This flaw enables attackers to inject malicious commands or read terminal output.
Recommendations
Update to version 0.16.0 or later.
Fix
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hermes-Agent