Nousresearch · Hermes-Agent · CVE-2026-85106
**Name of the Vulnerable Software and Affected Versions**
NousResearch hermes-agent version 0.18.0
**Description**
A server-side request forgery exists in the Link Title Fetch component. A remote attacker can manipulate the `url` argument within the `fetchLinkTitle()` function located in the apps/desktop/src/app/artifacts/index.tsx file to trigger this issue. Server-side request forgery is a flaw that allows an attacker to induce the server-side application to make requests to an unintended location.
**Recommendations**
As a temporary workaround, consider restricting the use of the `fetchLinkTitle()` function until a patch is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.