Skip to content
hermes-agentGHSA-99f9-j8r3-p853

hermes-agent: insecure default permissions

Medium5.5CVE-2026-53870 · Published Jun 17, 2026 · updated Jul 13, 2026

Hermes Agent before 0.16.0 creates response_store.db and webhook_subscriptions.json with world-readable permissions (mode 0o644), exposing conversation history and HMAC secrets to local users. Attackers with local filesystem access can read these files directly to obtain sensitive data including conversation history, tool payloads, prompts, and per-route HMAC secrets.

GitHub advisory

Affected versions

PackageAffectedFixed in
hermes-agent
PyPI
< 0.16.00.16.0
Details and references

More hermes-agent advisories

All hermes-agent
Advisory
hermes-agent: missing authentication
High7.5Jun 17
hermes-agent has an Injection issue
Low6.3Jun 1
hermes-agent has an Uncontrolled Resource Consumption issue
Medium5.3Jun 1
hermes-agent has an Injection issue
Low5.6Jun 1
hermes-agent has an Injection issue
Medium7.3Jun 1
hermes-agent has an Incorrect Comparison
Low5.3May 26

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.