Metrics
Affected Vendors & Products
Tue, 04 Aug 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 04 Aug 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was detected in NousResearch hermes-agent up to 2026.6.5. Affected by this issue is the function _check_slash_access of the file gateway/run.py of the component Quick Command Handler. The manipulation results in incorrect authorization. The attack can be launched remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | |
| Title | NousResearch hermes-agent Quick run.py _check_slash_access authorization | |
| First Time appeared |
Nousresearch
Nousresearch hermes-agent |
|
| Weaknesses | CWE-285 CWE-863 |
|
| CPEs | cpe:2.3:a:nousresearch:hermes-agent:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Nousresearch
Nousresearch hermes-agent |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-08-04T16:40:42.573Z
Reserved: 2026-08-04T07:35:35.152Z
Link: CVE-2026-18773
Updated: 2026-08-04T16:40:37.488Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-08-04T16:30:11Z