๐Ÿ” CVE Alert

CVE-2026-82021

HIGH 8.3

Hermes Agent 0.18.2 < 0.19.0 MCP Catalog Supply Chain RCE via Mutable Branch Reference

CVSS Score
8.3
EPSS Score
0.0%
EPSS Percentile
0th

Hermes Agent 0.18.2 prior to 0.19.0 contains a supply chain vulnerability in its bundled MCP catalog that allows a remote attacker to execute arbitrary code by compromising a third-party upstream repository referenced via a mutable branch rather than a pinned commit SHA. An attacker who compromises the upstream repository can propagate malicious code to every host that installs the affected catalog entry, with no further action required by the operator.

CWE CWE-494
Vendor nousresearch
Product hermes-agent
Published Aug 28, 2026
Last Updated Aug 29, 2026
Stay Ahead of the Next One

Get instant alerts for nousresearch hermes-agent

Be the first to know when new high vulnerabilities affecting nousresearch hermes-agent are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
Required
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

NousResearch / hermes-agent
0.18.2 < 0.19.0 2026.7.7.2 < 2026.7.20

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/NousResearch/hermes-agent/releases/tag/v2026.7.20 github.com: https://github.com/NousResearch/hermes-agent/pull/64463 github.com: https://github.com/NousResearch/hermes-agent/commit/9df5f879b4a5925c0f8f947e7e16ed8e845932c3 vulncheck.com: https://www.vulncheck.com/advisories/hermes-agent-mcp-catalog-supply-chain-rce-via-mutable-branch-reference

Credits

Zubair Ashraf (@zashraf1337), Helmet Security