PT-2026-85025 · Nousresearch · Hermes-Agent
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
NousResearch hermes-agent version 0.18.0
Description
A remote attack can be initiated against the Electron Main Process component by manipulating the
resourceBufferFromUrl() function located in the apps/desktop/electron/main.ts file, leading to the allocation of resources.Recommendations
Update NousResearch hermes-agent to a version where the
resourceBufferFromUrl() function is patched or removed.
As a temporary mitigation, restrict remote access to the Electron Main Process component.Fix
Resource Exhaustion
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Hermes-Agent