๐Ÿ” CVE Alert

CVE-2026-17432

MEDIUM 5.0

NousResearch hermes-agent SimpleX Gateway Authorization adapter.py access control

CVSS Score
5.0
EPSS Score
0.0%
EPSS Percentile
0th

A vulnerability was detected in NousResearch hermes-agent 2026.6.5. Affected by this vulnerability is an unknown functionality of the file hermes-agent/plugins/platforms/simplex/adapter.py of the component SimpleX Gateway Authorization. The manipulation of the argument contactId results in improper access controls. The attack may be launched remotely. A high complexity level is associated with this attack. The exploitation appears to be difficult. The exploit is now public and may be used. The patch is identified as 490c486ff65b766d9de0fe0e6f26e1778aaa8fb3. Applying a patch is advised to resolve this issue.

CWE CWE-284 CWE-266
Vendor nousresearch
Product hermes-agent
Published Jul 26, 2026
Stay Ahead of the Next One

Get instant alerts for nousresearch hermes-agent

Be the first to know when new medium vulnerabilities affecting nousresearch hermes-agent are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

NousResearch / hermes-agent
2026.6.5

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
vuldb.com: https://vuldb.com/vuln/383065 vuldb.com: https://vuldb.com/vuln/383065/cti vuldb.com: https://vuldb.com/cve/CVE-2026-17432 vuldb.com: https://vuldb.com/submit/862424 github.com: https://github.com/NousResearch/hermes-agent/issues/44730 github.com: https://github.com/NousResearch/hermes-agent/pull/41246 github.com: https://github.com/NousResearch/hermes-agent/issues/44729 github.com: https://github.com/NousResearch/hermes-agent/commit/490c486ff65b766d9de0fe0e6f26e1778aaa8fb3 github.com: https://github.com/NousResearch/hermes-agent/

Credits

๐Ÿ” Erichen-x (VulDB User)