Skip to content
hermes-agentGHSA-4pqm-j46f-795x

Hermes Agent contains a DNS rebinding vulnerability in WebSocket endpoints that allows remote attackers to bypass Host and Origin validation

High7.5CVE-2026-53869 · Published Jun 17, 2026 · updated Jul 13, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
hermes-agent
PyPI
< 0.16.00.16.0
Details and references

Hermes Agent before 0.16.0 contains a DNS rebinding vulnerability in WebSocket endpoints that allows remote attackers to bypass Host and Origin validation. FastAPI HTTP middleware does not execute for WebSocket upgrade requests on /api/pty, /api/ws, /api/pub, and /api/events endpoints, enabling attackers to exploit DNS rebinding and inject malicious commands or read terminal output.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-306
Also known as
CVE-2026-53869, PYSEC-2026-2510

More hermes-agent advisories

All
DateAdvisory
Jun 17Hermes Agent creates response_store.db and webhook_subscriptions.json with world-readable permissions (mode 0o644)
CVE-2026-53870Medium5.5fixed in 0.16.0
Jun 1hermes-agent has an Injection issue
CVE-2026-10223Low6.3fixed in 0.15.0
Jun 1hermes-agent has an Uncontrolled Resource Consumption issue
CVE-2026-10224Medium5.3no fix yet
Jun 1hermes-agent has an Injection issue
CVE-2026-10222Low5.6fixed in 0.18.0
Jun 1hermes-agent has an Injection issue
CVE-2026-10221Medium7.3no fix yet
May 26hermes-agent has an Incorrect Comparison
CVE-2026-9369Low5.3fixed in 0.15.0

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.