CVE-2026-15311
LOWNousResearch hermes-agent Matrix Adapter matrix.py MatrixAdapter._markdown_to_html cross site scripting
Title source: cnaDescription
A vulnerability was identified in NousResearch hermes-agent up to 2026.5.29.2. Affected by this issue is the function MatrixAdapter._markdown_to_html of the file gateway/platforms/matrix.py of the component Matrix Adapter. Such manipulation leads to cross site scripting. The attack can be executed remotely. The exploit is publicly available and might be used. The pull request to fix this issue awaits acceptance.
References (7)
Core 7
Core References
Product product
https://github.com/NousResearch/hermes-agent/
Vdb Entry, Technical Description vdb-entry
technical-description
VDB-377247 | NousResearch hermes-agent Matrix Adapter matrix.py MatrixAdapter._markdown_to_html cross site scripting
https://vuldb.com/vuln/377247
Signature, Permissions Required signature
permissions-required
VDB-377247 | CTI Indicators (IOB, IOC, TTP, IOA)
https://vuldb.com/vuln/377247/cti
Third Party Advisory third-party-advisory
CVE-2026-15311 | CVE Analysis and Report
https://vuldb.com/cve/CVE-2026-15311
Third Party Advisory third-party-advisory
Submit #852843 | NousResearch hermes-agent 2026.5.29.2 Cross-site Scripting (CWE-79)
https://vuldb.com/submit/852843
Exploit exploit
issue-tracking
https://github.com/NousResearch/hermes-agent/issues/42667
Patch issue-tracking
patch
https://github.com/NousResearch/hermes-agent/pull/42759
Scores
CVSS v3
3.5
EPSS
0.0020
EPSS Percentile
10.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-79
CWE-94
Status
published
Products (3)
NousResearch/hermes-agent
2026.5.29.0
NousResearch/hermes-agent
2026.5.29.1
NousResearch/hermes-agent
2026.5.29.2
Published
Jul 10, 2026
Tracked Since
Jul 10, 2026