CVE-2026-82020

Hermes Agent 0.16.0 prior to 0.17.0 contains an improper path restriction vulnerability that allows attackers who can influence ingested message content to overwrite the credential store by bypassing sensitive-path guards that excluded the auth.json file. Attackers can craft malicious messages directing the agent's file-write tooling to overwrite the credential store without triggering any path-based protection, enabling credential tampering or unauthorized access.

Scoring

Severity
HIGH
CVSS base score
7.6
CVSS vector
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
EPSS probability
0.33%
CWE
CWE-552
Published
2026-08-28
Last modified
2026-09-01

Affected products

Weakness type

Related vulnerabilities

Markdown version · Browse all CVEs