๐Ÿ” CVE Alert

CVE-2026-82020

MEDIUM 6.8

Hermes Agent 0.16.0 < 0.17.0 Credential Store Overwrite via File-Write Tool

CVSS Score
6.8
EPSS Score
0.0%
EPSS Percentile
0th

Hermes Agent 0.16.0 prior to 0.17.0 contains an improper path restriction vulnerability that allows attackers who can influence ingested message content to overwrite the credential store by bypassing sensitive-path guards that excluded the auth.json file. Attackers can craft malicious messages directing the agent's file-write tooling to overwrite the credential store without triggering any path-based protection, enabling credential tampering or unauthorized access.

CWE CWE-552
Vendor nousresearch
Product hermes-agent
Published Aug 28, 2026
Last Updated Aug 29, 2026
Stay Ahead of the Next One

Get instant alerts for nousresearch hermes-agent

Be the first to know when new medium vulnerabilities affecting nousresearch hermes-agent are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None

Affected Versions

NousResearch / hermes-agent
0.16.0 < 0.17.0 2026.6.5 < 2026.6.19

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/NousResearch/hermes-agent/releases/tag/v2026.6.19 github.com: https://github.com/NousResearch/hermes-agent/pull/45821 github.com: https://github.com/NousResearch/hermes-agent/commit/da28d5d113956dcf803d5cff552a120740a96a59 github.com: https://github.com/NousResearch/hermes-agent/commit/2b67e96aec2aa2abd5e94b544cda8e564c75f9f5 vulncheck.com: https://www.vulncheck.com/advisories/hermes-agent-credential-store-overwrite-via-file-write-tool

Credits

Zubair Ashraf (@zashraf1337), Helmet Security