CVE-2026-18773

MEDIUM

NousResearch hermes-agent Quick run.py _check_slash_access authorization

Title source: cna
STIX 2.1

Description

A vulnerability was detected in NousResearch hermes-agent up to 2026.6.5. Affected by this issue is the function _check_slash_access of the file gateway/run.py of the component Quick Command Handler. The manipulation results in incorrect authorization. The attack can be launched remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

References (5)

Core 5
Core References
Vdb Entry, Technical Description vdb-entry technical-description
VDB-385783 | NousResearch hermes-agent Quick run.py _check_slash_access authorization
https://vuldb.com/vuln/385783
Signature, Permissions Required signature permissions-required
VDB-385783 | CTI Indicators (IOB, IOC, IOA)
https://vuldb.com/vuln/385783/cti
Third Party Advisory third-party-advisory
CVE-2026-18773 | CVE Analysis and Report
https://vuldb.com/cve/CVE-2026-18773
Third Party Advisory third-party-advisory
Submit #856874 | NousResearch hermes-agent 2026.6.5 Incorrect Authorization (CWE-863)
https://vuldb.com/submit/856874

Scores

CVSS v3 6.3
EPSS 0.0020
EPSS Percentile 10.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-285 CWE-863
Status published
Products (6)
NousResearch/hermes-agent 2026.6.0
NousResearch/hermes-agent 2026.6.1
NousResearch/hermes-agent 2026.6.2
NousResearch/hermes-agent 2026.6.3
NousResearch/hermes-agent 2026.6.4
NousResearch/hermes-agent 2026.6.5
Published Aug 04, 2026
Tracked Since Aug 04, 2026