PT-2026-83283 · Unknown · Hermes-Agent
CVSS v4.0
7.6
High
| Vector | AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Hermes Agent version 0.16.0
Description
An improper path restriction exists that allows attackers who can influence ingested message content to overwrite the credential store. This occurs by bypassing sensitive-path guards that failed to exclude the
auth.json file. Attackers can craft malicious messages to direct the agent's file-write tooling to overwrite the credential store, which may lead to credential tampering or unauthorized access.Recommendations
Update Hermes Agent to version 0.17.0.
Exploit
Fix
Files Accessible to External Parties
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hermes-Agent