Vulnerabilidades en NousResearch

44 resultados
Análisis Vexday

NousResearch apresenta 29 vulnerabilidades catalogadas, todas publicadas nos últimos 90 dias, indicando exposição recente e contínua. Embora nenhuma esteja sob exploração ativa conhecida ou classificada como crítica, a dominância de CWE-74 (manipulação imprópria de entrada) sugere falhas sistemáticas em validação de dados que requerem remediação prioritária. O volume concentrado em curto período aponta para descoberta intensiva ou divulgação em massa de um vetor específico.

CVE-2026-9367MEDIUMNousResearch hermes-agent terminal_tool approval.py detect_dangerous_command os command injectionEPSS 1.7%CVE-2026-71963HIGHHermes Agent 0.18.2 - 0.21.0 RCE via git core.fsmonitor Config InjectionEPSS 0.9%CVE-2026-14628MEDIUMNousResearch hermes-agent Live Webhook Endpoint base.py extract_media path traversalEPSS 0.8%CVE-2026-9351MEDIUMNousResearch hermes-agent read_file Tool file_tools.py _is_blocked_device path traversalEPSS 0.7%CVE-2026-53869HIGHHermes Agent < 0.16.0 - DNS Rebinding Bypass via WebSocket EndpointsEPSS 0.6%CVE-2026-14627MEDIUMNousResearch hermes-agent Discord Platform Integration discord.py DiscordAdapter._is_allowed_user improper authenticationEPSS 0.6%CVE-2026-7396MEDIUMNousResearch hermes-agent WeChat Work Platform Adapter wecom.py path traversalEPSS 0.5%CVE-2026-14783MEDIUMNousResearch hermes-agent skills_tool.py skill_view path traversalEPSS 0.5%CVE-2026-14626MEDIUMNousResearch hermes-agent HTTP API run_agent.py AIAgent.run_conversation denial of serviceEPSS 0.5%CVE-2026-84287MEDIUMNousResearch hermes-agent Session Chat api_server.py denial of serviceEPSS 0.4%CVE-2026-9368MEDIUMNousResearch hermes-agent Environment Variable code_execution_tool.py execute_code sandboxEPSS 0.4%CVE-2026-14625MEDIUMNousResearch hermes-agent server.py shell.exec protection mechanismEPSS 0.4%CVE-2026-14617LOWNousResearch hermes-agent Streaming Reasoning Tag Filter stream_consumer.py GatewayStreamConsumer._filter_and_accumulate case sensitivityEPSS 0.4%CVE-2026-85107MEDIUMNousResearch hermes-agent Electron Main Process main.ts resourceBufferFromUrl allocation of resourcesEPSS 0.4%CVE-2026-10224MEDIUMNousResearch hermes-agent Webhook Endpoint feishu.py _handle_webhook_request resource consumptionEPSS 0.4%CVE-2026-85105MEDIUMNousResearch hermes-agent Session Management s71.py _sess_nowait authorizationEPSS 0.4%CVE-2026-7113MEDIUMNousResearch hermes-agent Webhooks Endpoint webhook.py missing authenticationEPSS 0.4%CVE-2026-7112MEDIUMNousResearch hermes-agent API_SERVER_KEY api_server.py _check_auth improper authenticationEPSS 0.4%CVE-2026-15311MEDIUMNousResearch hermes-agent Matrix Adapter matrix.py MatrixAdapter._markdown_to_html cross site scriptingEPSS 0.4%CVE-2026-9354MEDIUMNousResearch hermes-agent Slack Agent/Mattermost Agent escape outputEPSS 0.3%