PT-2026-67755 · Nousresearch · Hermes-Agent

·

CVE-2026-18775

·

Published

2026-08-04

·

Updated

2026-08-04

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
A vulnerability has been found in NousResearch hermes-agent up to 0.16.0. This vulnerability affects the function browser snapshot of the file tools/browser tool.py of the component Browser Tooling. Such manipulation leads to server-side request forgery. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-18775

Affected Products

Hermes-Agent