Impact
The _scan_memory_content function in NousResearch hermes-agent contains an injection vulnerability that can be triggered remotely. Exploitation may allow an attacker to inject malicious payloads into the memory scanning process, potentially leading to unintended disruptive behavior. The weakness is identified as a type of input injection consistent with CWE-707 and CWE-74.
Affected Systems
The vulnerability affects all releases of NousResearch hermes-agent up to and including version 2026.4.30. No earlier or later versions are listed as affected.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, and the lack of an EPSS score or KEV listing suggests limited current exploitation data. However, the description notes a publicly available exploit and the possibility of remote initiation, which raises the practical risk for systems running the vulnerable software. Attackers can force the vulnerable function to process crafted input, enabling the injection attack.
OpenCVE Enrichment