hermes-agentGHSA-4pqm-j46f-795x
Hermes Agent contains a DNS rebinding vulnerability in WebSocket endpoints that allows remote attackers to bypass Host and Origin validation
High7.5CVE-2026-53869 · Published Jun 17, 2026 · updated Jul 13, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| hermes-agent PyPI | < 0.16.0 | 0.16.0 |
Details and references
Hermes Agent before 0.16.0 contains a DNS rebinding vulnerability in WebSocket endpoints that allows remote attackers to bypass Host and Origin validation. FastAPI HTTP middleware does not execute for WebSocket upgrade requests on /api/pty, /api/ws, /api/pub, and /api/events endpoints, enabling attackers to exploit DNS rebinding and inject malicious commands or read terminal output.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-306
- Also known as
- CVE-2026-53869, PYSEC-2026-2510
- nvd.nist.gov/vuln/detail/CVE-2026-53869
- github.com/NousResearch/hermes-agent/pull/30221
- github.com/NousResearch/hermes-agent/pull/31685
- github.com/NousResearch/hermes-agent/commit/d9ec90585cf7616b5972e44cf8d92bb569fc3feb
- github.com/NousResearch/hermes-agent
- github.com/NousResearch/hermes-agent/releases/tag/v2026.6.5
- www.vulncheck.com/advisories/hermes-agent-dns-rebinding-bypass-via-websocket-endpoints
More hermes-agent advisories
All| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jun 17 | Hermes Agent creates response_store.db and webhook_subscriptions.json with world-readable permissions (mode 0o644) CVE-2026-53870Medium5.5fixed in 0.16.0 | Medium5.5 | 0.16.0 |
| Jun 1 | hermes-agent has an Injection issue CVE-2026-10223Low6.3fixed in 0.15.0 | Low6.3 | 0.15.0 |
| Jun 1 | hermes-agent has an Uncontrolled Resource Consumption issue CVE-2026-10224Medium5.3no fix yet | Medium5.3 | No fix yet |
| Jun 1 | hermes-agent has an Injection issue CVE-2026-10222Low5.6fixed in 0.18.0 | Low5.6 | 0.18.0 |
| Jun 1 | hermes-agent has an Injection issue CVE-2026-10221Medium7.3no fix yet | Medium7.3 | No fix yet |
| May 26 | hermes-agent has an Incorrect Comparison CVE-2026-9369Low5.3fixed in 0.15.0 | Low5.3 | 0.15.0 |