hermes-agentGHSA-pgp4-xr4j-h5cg
hermes-agent has an Injection issue
Medium7.3CVE-2026-9366 · Published May 26, 2026 · updated Jul 13, 2026
A vulnerability was found in NousResearch hermes-agent 2026.4.23. The impacted element is the function _scan_context_content of the file agent/prompt_builder.py. The manipulation results in injection. The attack may be performed from remote. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| hermes-agent PyPI | < 0.15.0 | 0.15.0 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-74
- Also known as
- CVE-2026-9366, PYSEC-2026-2514
More hermes-agent advisories
All hermes-agent| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jun 1 | hermes-agent has an Uncontrolled Resource Consumption issue | Medium5.3 | No fix yet |
| Jun 1 | hermes-agent has an Injection issue | Medium7.3 | No fix yet |
| Jun 1 | hermes-agent has an Injection issue | Low5.6 | 0.18.0 |
| May 26 | hermes-agent has an Incorrect Comparison | Low5.3 | 0.15.0 |
| May 26 | hermes-agent has a sandbox issue | Medium7.3 | 0.11.0 |
| May 26 | hermes-agent has an Injection issue | Medium7.3 | 0.15.0 |