Vulnerabilities in NousResearch
35 resultsVexday analysis
NousResearch apresenta 29 vulnerabilidades catalogadas, todas publicadas nos últimos 90 dias, indicando exposição recente e contínua. Embora nenhuma esteja sob exploração ativa conhecida ou classificada como crítica, a dominância de CWE-74 (manipulação imprópria de entrada) sugere falhas sistemáticas em validação de dados que requerem remediação prioritária. O volume concentrado em curto período aponta para descoberta intensiva ou divulgação em massa de um vetor específico.
CVE-2026-10222MEDIUMNousResearch hermes-agent config.py _sanitize_env_lines injectionEPSS 0.3%CVE-2026-14617LOWNousResearch hermes-agent Streaming Reasoning Tag Filter stream_consumer.py GatewayStreamConsumer._filter_and_accumulate case sensitivityEPSS 0.2%CVE-2026-17432LOWNousResearch hermes-agent SimpleX Gateway Authorization adapter.py access controlEPSS 0.2%CVE-2026-9369MEDIUMNousResearch hermes-agent CLI web-dashboard web_server.py _discover_dashboard_plugins comparisonEPSS 0.2%CVE-2026-10223MEDIUMNousResearch hermes-agent memory_tool.py _scan_memory_content injectionEPSS 0.2%CVE-2026-11461MEDIUMNousResearch hermes-agent resume Endpoint hermes_state.py resolve_session_by_title authorizationEPSS 0.2%CVE-2026-14625MEDIUMNousResearch hermes-agent server.py shell.exec protection mechanismEPSS 0.2%CVE-2026-15311MEDIUMNousResearch hermes-agent Matrix Adapter matrix.py MatrixAdapter._markdown_to_html cross site scriptingEPSS 0.2%CVE-2026-18774MEDIUMNousResearch hermes-agent xAI Image Generation Provider image_gen_provider.py save_url_image server-side request forgeryEPSS 0.2%CVE-2026-18773MEDIUMNousResearch hermes-agent Quick run.py _check_slash_access authorizationEPSS 0.2%CVE-2026-10548MEDIUMNousResearch hermes-agent Credential Pool Synchronization credential_pool.py _sync_anthropic_entry_from_credentials_file improper authenticationEPSS 0.1%CVE-2026-7397MEDIUMNousResearch hermes-agent file_tools.py _check_sensitive_path symlinkEPSS 0.1%CVE-2026-53870MEDIUMHermes Agent < 0.16.0 - Sensitive File Permission Vulnerability in Store FilesEPSS 0.1%CVE-2026-18993MEDIUMNousResearch hermes-agent Memory Toolset model_tools.py access controlEPSS —CVE-2026-18976MEDIUMNousResearch hermes-agent disabled_toolsets agent_init.py get_tool_definitions privileges assignmentEPSS —