PT-2026-83284 · Unknown · Hermes-Agent
CVSS v4.0
9.0
Critical
| Vector | AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H |
Name of the Vulnerable Software and Affected Versions
Hermes Agent versions 0.18.2 through 0.18.x
Description
A supply chain issue exists in the bundled MCP catalog. A remote attacker can execute arbitrary code by compromising a third-party upstream repository that is referenced via a mutable branch instead of a pinned commit SHA. This allows malicious code to be propagated to every host that installs the affected catalog entry without requiring any action from the operator.
Recommendations
Update Hermes Agent to version 0.19.0 or later.
Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hermes-Agent