CVE-2026-18773
MEDIUMNousResearch hermes-agent Quick run.py _check_slash_access authorization
Title source: cnaDescription
A vulnerability was detected in NousResearch hermes-agent up to 2026.6.5. Affected by this issue is the function _check_slash_access of the file gateway/run.py of the component Quick Command Handler. The manipulation results in incorrect authorization. The attack can be launched remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
References (5)
Core 5
Core References
Vdb Entry, Technical Description vdb-entry
technical-description
VDB-385783 | NousResearch hermes-agent Quick run.py _check_slash_access authorization
https://vuldb.com/vuln/385783
Signature, Permissions Required signature
permissions-required
VDB-385783 | CTI Indicators (IOB, IOC, IOA)
https://vuldb.com/vuln/385783/cti
Third Party Advisory third-party-advisory
CVE-2026-18773 | CVE Analysis and Report
https://vuldb.com/cve/CVE-2026-18773
Third Party Advisory third-party-advisory
Submit #856874 | NousResearch hermes-agent 2026.6.5 Incorrect Authorization (CWE-863)
https://vuldb.com/submit/856874
Scores
CVSS v3
6.3
EPSS
0.0020
EPSS Percentile
10.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-285
CWE-863
Status
published
Products (6)
NousResearch/hermes-agent
2026.6.0
NousResearch/hermes-agent
2026.6.1
NousResearch/hermes-agent
2026.6.2
NousResearch/hermes-agent
2026.6.3
NousResearch/hermes-agent
2026.6.4
NousResearch/hermes-agent
2026.6.5
Published
Aug 04, 2026
Tracked Since
Aug 04, 2026