Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pgp4-xr4j-h5cg

Опубликовано: 26 мая 2026
Источник: github
Github: Прошло ревью
CVSS4: 5.5
CVSS3: 7.3

Описание

hermes-agent has an Injection issue

A vulnerability was found in NousResearch hermes-agent 2026.4.23. The impacted element is the function _scan_context_content of the file agent/prompt_builder.py. The manipulation results in injection. The attack may be performed from remote. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

Пакеты

Наименование

hermes-agent

pip
Затронутые версииВерсия исправления

< 0.15.0

0.15.0

EPSS

Процентиль: 23%
0.00305
Низкий

5.5 Medium

CVSS4

7.3 High

CVSS3

Дефекты

CWE-74

Связанные уязвимости

CVSS3: 7.3
nvd
2 месяца назад

A vulnerability was found in NousResearch hermes-agent 2026.4.23. The impacted element is the function _scan_context_content of the file agent/prompt_builder.py. The manipulation results in injection. The attack may be performed from remote. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

EPSS

Процентиль: 23%
0.00305
Низкий

5.5 Medium

CVSS4

7.3 High

CVSS3

Дефекты

CWE-74