Nousresearch · Hermes-Agent · CVE-2026-18976
**Name of the Vulnerable Software and Affected Versions**
NousResearch hermes-agent versions prior to 0.16.1
**Description**
A remote attack can lead to incorrect privilege assignment. This issue occurs within the `disabled toolsets` Handler, specifically affecting the `get tool definitions()` function located in the `agent/agent init.py` file.
**Recommendations**
Update NousResearch hermes-agent to a version later than 0.16.0.
As a temporary workaround, restrict access to the `get tool definitions()` function in the `agent/agent init.py` file.