hinotoi-agent
28 exploits
Active since Apr 2026
DeepTutor < 1.4.10 - Insecure Default Grants Unrestricted MCP Tool Access to Non-Admin Users
CVSS 8.8
NanoClaw < 2.1.17 - Privilege Escalation via Unverified Approval Response Handler
CVSS 6.5
NanoClaw < 2.1.17 - Arbitrary File Read via Symlink Following in forwardAttachedFiles
CVSS 5.5
NanoClaw < 2.1.17 - Privilege Escalation via Unauthorized create_agent System Action
CVSS 5.5
NanoClaw < 2.1.0 - Privilege Escalation via Forged Channel Approval Callback
CVSS 5.4
OpenHarness - Cross-Session Disclosure via /resume and /summary Commands
CVSS 6.5
OpenHarness - Prompt Injection via /issue and /pr_comments Slash Commands
CVSS 5.4
Hermes WebUI < 0.51.468 - Resource Exhaustion via Unauthenticated OAuth Flow Endpoint
CVSS 5.3
Hermes Agent < 0.16.0 - World-Readable Store Files Expose Secrets
CVSS 5.5
Hermes WebUI < 0.51.368 - Profile-Scoped Authorization Bypass via Forged hermes_profile Cookie
CVSS 8.1
Hermes WebUI < 0.51.409 - Unauthenticated Passkey Registration via Authentication Bypass
CVSS 9.1
Hermes WebUI < 0.51.443 - Broken Access Control in /api/session Endpoint
CVSS 6.5
Hermes WebUI < 0.51.443 - Cross-Profile Session Data Exfiltration via Session Export Endpoint
CVSS 6.5
Hermes WebUI < 0.51.358 Unauthenticated Password Takeover via /api/settings
CVSS 9.4
Summarize < 0.17.0 Disk Exhaustion via Uncapped Media Download
CVSS 4.3
Summarize < 0.17.0 SSRF via podcast:transcript URL fetch
CVSS 7.4
Hermes WebUI < 0.51.269 Profile Isolation Bypass via sessions search
CVSS 6.5
Hermes WebUI < 0.51.269 Workspace Boundary Bypass via api/workspace.py
CVSS 7.7
Hermes WebUI < 0.51.303 TOCTOU Race Condition via git_discard
CVSS 5.0
Hermes WebUI < 0.51.311 RCE via Git Configuration Injection
CVSS 8.8
Hermes WebUI before 0.51.221 Path Traversal via Symlink Workspace Bypass
CVSS 6.5
Summarize < 0.15.1 Unapproved Browser Automation Execution
CVSS 5.4
Heym < 0.0.21 Path Traversal File Upload via upload_file()
CVSS 7.6
Heym < 0.0.21 Authorization Bypass in Workflow Execution
CVSS 7.1
Heym < 0.0.21 Sandbox Escape via Python Introspection
CVSS 8.8