Vulnerabilidades en NousResearch
44 resultadosAnálisis Vexday
NousResearch apresenta 29 vulnerabilidades catalogadas, todas publicadas nos últimos 90 dias, indicando exposição recente e contínua. Embora nenhuma esteja sob exploração ativa conhecida ou classificada como crítica, a dominância de CWE-74 (manipulação imprópria de entrada) sugere falhas sistemáticas em validação de dados que requerem remediação prioritária. O volume concentrado em curto período aponta para descoberta intensiva ou divulgação em massa de um vetor específico.
CVE-2026-82020HIGHHermes Agent 0.16.0 < 0.17.0 Credential Store Overwrite via File-Write ToolEPSS 0.3%CVE-2026-9366MEDIUMNousResearch hermes-agent prompt_builder.py _scan_context_content injectionEPSS 0.3%CVE-2026-9353MEDIUMNousResearch hermes-agent Skills Guard Multi-Word Prompt skills_guard.py injectionEPSS 0.3%CVE-2026-10220MEDIUMNousResearch hermes-agent skills_tool.py skill_view injectionEPSS 0.3%CVE-2026-10221MEDIUMNousResearch hermes-agent run_agent.py _compress_context injectionEPSS 0.3%CVE-2026-9352MEDIUMNousResearch hermes-agent Messaging Gateway local.py _make_run_env information disclosureEPSS 0.3%CVE-2026-9350MEDIUMNousResearch hermes-agent Batch Runner approval.py check_all_command_guards authorizationEPSS 0.3%CVE-2026-18775MEDIUMNousResearch hermes-agent Browser Tooling browser_tool.py browser_snapshot server-side request forgeryEPSS 0.3%CVE-2026-84289MEDIUMNousResearch hermes-agent MCP Tool mcp_tool.py list_tools memory allocationEPSS 0.3%CVE-2026-84288MEDIUMNousResearch hermes-agent ACP Prompt Workflow session.py HermesACPAgent.prompt denial of serviceEPSS 0.3%CVE-2026-10222MEDIUMNousResearch hermes-agent config.py _sanitize_env_lines injectionEPSS 0.3%CVE-2026-17432LOWNousResearch hermes-agent SimpleX Gateway Authorization adapter.py access controlEPSS 0.2%CVE-2026-9369MEDIUMNousResearch hermes-agent CLI web-dashboard web_server.py _discover_dashboard_plugins comparisonEPSS 0.2%CVE-2026-10223MEDIUMNousResearch hermes-agent memory_tool.py _scan_memory_content injectionEPSS 0.2%CVE-2026-82021CRITICALHermes Agent 0.18.2 < 0.19.0 MCP Catalog Supply Chain RCE via Mutable Branch ReferenceEPSS 0.2%CVE-2026-11461MEDIUMNousResearch hermes-agent resume Endpoint hermes_state.py resolve_session_by_title authorizationEPSS 0.2%CVE-2026-18993MEDIUMNousResearch hermes-agent Memory Toolset model_tools.py access controlEPSS 0.2%CVE-2026-18976MEDIUMNousResearch hermes-agent disabled_toolsets agent_init.py get_tool_definitions privileges assignmentEPSS 0.2%CVE-2026-85106MEDIUMNousResearch hermes-agent Link Title Fetch index.tsx fetchLinkTitle server-side request forgeryEPSS 0.2%CVE-2026-18773MEDIUMNousResearch hermes-agent Quick run.py _check_slash_access authorizationEPSS 0.2%