Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4pqm-j46f-795x

Опубликовано: 17 июн. 2026
Источник: github
Github: Прошло ревью
CVSS4: 8.7
CVSS3: 7.5

Описание

Hermes Agent contains a DNS rebinding vulnerability in WebSocket endpoints that allows remote attackers to bypass Host and Origin validation

Hermes Agent before 0.16.0 contains a DNS rebinding vulnerability in WebSocket endpoints that allows remote attackers to bypass Host and Origin validation. FastAPI HTTP middleware does not execute for WebSocket upgrade requests on /api/pty, /api/ws, /api/pub, and /api/events endpoints, enabling attackers to exploit DNS rebinding and inject malicious commands or read terminal output.

Пакеты

Наименование

hermes-agent

pip
Затронутые версииВерсия исправления

< 0.16.0

0.16.0

EPSS

Процентиль: 47%
0.00592
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-306

Связанные уязвимости

CVSS3: 7.5
nvd
3 месяца назад

Hermes Agent before 0.16.0 contains a DNS rebinding vulnerability in WebSocket endpoints that allows remote attackers to bypass Host and Origin validation. FastAPI HTTP middleware does not execute for WebSocket upgrade requests on /api/pty, /api/ws, /api/pub, and /api/events endpoints, enabling attackers to exploit DNS rebinding and inject malicious commands or read terminal output.

EPSS

Процентиль: 47%
0.00592
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-306