PT-2026-64787 · Nousresearch · Hermes-Agent
CVSS v3.1
5.0
Medium
| Vector | AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
NousResearch hermes-agent version 2026.6.5
Description
Improper access controls exist within the SimpleX Gateway Authorization component, specifically in the file
hermes-agent/plugins/platforms/simplex/adapter.py. A remote attacker can exploit this by manipulating the contactId argument. This attack is characterized by high complexity and is considered difficult to execute.Recommendations
Apply patch 490c486ff65b766d9de0fe0e6f26e1778aaa8fb3 for version 2026.6.5.
Exploit
Fix
Improper Access Control
Incorrect Privilege Assignment
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Hermes-Agent