« Volver al listado

Hermes Agent

Hermes Agent: vulnerabilidades y CVE

Hermes Agent tiene 5 vulnerabilidades publicadas, 5 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE5
Últimos 12 meses5
Críticas1
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-71963Alta (8.6)0.86%—3 sept 2026
Hermes Agent 0.18.2 through 0.21.0, fixed in commit f6234d0, contains a remote code execution vulnerability that allows attackers to execute arbitrary OS commands by supplying a malicious repository with a crafted…
CVE-2026-82021Crítica (9)0.34%—28 ago 2026
Hermes Agent 0.18.2 prior to 0.19.0 contains a supply chain vulnerability in its bundled MCP catalog that allows a remote attacker to execute arbitrary code by compromising a third-party upstream repository referenced…
CVE-2026-82020Alta (7.6)0.43%—28 ago 2026
Hermes Agent 0.16.0 prior to 0.17.0 contains an improper path restriction vulnerability that allows attackers who can influence ingested message content to overwrite the credential store by bypassing sensitive-path…
CVE-2026-53870Media (6.8)0.15%—17 jun 2026
Hermes Agent before 0.16.0 creates response_store.db and webhook_subscriptions.json with world-readable permissions (mode 0o644), exposing conversation history and HMAC secrets to local users. Attackers with local…
CVE-2026-53869Alta (8.7)0.81%—17 jun 2026
Hermes Agent before 0.16.0 contains a DNS rebinding vulnerability in WebSocket endpoints that allows remote attackers to bypass Host and Origin validation. FastAPI HTTP middleware does not execute for WebSocket upgrade…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1059 Command and Scripting Interpreter2
  2. T1203 Exploitation for Client Execution2
  3. T1078 Valid Accounts1
  4. T1190 Exploit Public-Facing Application1
  5. T1195 Supply Chain Compromise1
  6. T1556 Modify Authentication Process1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.