Vulnerabilidades em NousResearch

33 resultados
Análise Vexday

NousResearch apresenta 29 vulnerabilidades catalogadas, todas publicadas nos últimos 90 dias, indicando exposição recente e contínua. Embora nenhuma esteja sob exploração ativa conhecida ou classificada como crítica, a dominância de CWE-74 (manipulação imprópria de entrada) sugere falhas sistemáticas em validação de dados que requerem remediação prioritária. O volume concentrado em curto período aponta para descoberta intensiva ou divulgação em massa de um vetor específico.

CVE-2026-9367MEDIUMNousResearch hermes-agent terminal_tool approval.py detect_dangerous_command os command injectionEPSS 1.7%CVE-2026-9351MEDIUMNousResearch hermes-agent read_file Tool file_tools.py _is_blocked_device path traversalEPSS 0.7%CVE-2026-14628MEDIUMNousResearch hermes-agent Live Webhook Endpoint base.py extract_media path traversalEPSS 0.7%CVE-2026-53869HIGHHermes Agent < 0.16.0 - DNS Rebinding Bypass via WebSocket EndpointsEPSS 0.6%CVE-2026-7396MEDIUMNousResearch hermes-agent WeChat Work Platform Adapter wecom.py path traversalEPSS 0.5%CVE-2026-9368MEDIUMNousResearch hermes-agent Environment Variable code_execution_tool.py execute_code sandboxEPSS 0.4%CVE-2026-10224MEDIUMNousResearch hermes-agent Webhook Endpoint feishu.py _handle_webhook_request resource consumptionEPSS 0.4%CVE-2026-14627MEDIUMNousResearch hermes-agent Discord Platform Integration discord.py DiscordAdapter._is_allowed_user improper authenticationEPSS 0.4%CVE-2026-7113MEDIUMNousResearch hermes-agent Webhooks Endpoint webhook.py missing authenticationEPSS 0.4%CVE-2026-7112MEDIUMNousResearch hermes-agent API_SERVER_KEY api_server.py _check_auth improper authenticationEPSS 0.4%CVE-2026-9354MEDIUMNousResearch hermes-agent Slack Agent/Mattermost Agent escape outputEPSS 0.3%CVE-2026-14783MEDIUMNousResearch hermes-agent skills_tool.py skill_view path traversalEPSS 0.3%CVE-2026-9366MEDIUMNousResearch hermes-agent prompt_builder.py _scan_context_content injectionEPSS 0.3%CVE-2026-9353MEDIUMNousResearch hermes-agent Skills Guard Multi-Word Prompt skills_guard.py injectionEPSS 0.3%CVE-2026-10221MEDIUMNousResearch hermes-agent run_agent.py _compress_context injectionEPSS 0.3%CVE-2026-10220MEDIUMNousResearch hermes-agent skills_tool.py skill_view injectionEPSS 0.3%CVE-2026-9352MEDIUMNousResearch hermes-agent Messaging Gateway local.py _make_run_env information disclosureEPSS 0.3%CVE-2026-9350MEDIUMNousResearch hermes-agent Batch Runner approval.py check_all_command_guards authorizationEPSS 0.3%CVE-2026-14626MEDIUMNousResearch hermes-agent HTTP API run_agent.py AIAgent.run_conversation denial of serviceEPSS 0.3%CVE-2026-18775MEDIUMNousResearch hermes-agent Browser Tooling browser_tool.py browser_snapshot server-side request forgeryEPSS 0.3%