PT-2026-67731 · Nousresearch · Hermes-Agent

·

CVE-2026-18773

·

Published

2026-08-04

·

Updated

2026-08-04

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions NousResearch hermes-agent versions prior to 2026.6.6
Description An issue in the Quick Command Handler component allows for incorrect authorization. The flaw exists within the check slash access() function located in the gateway/run.py file and can be exploited remotely.
Recommendations As a temporary workaround, restrict access to the check slash access() function until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Incorrect Authorization

Improper Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-18773

Affected Products

Hermes-Agent