Description
9router 0.4.1 through 0.5.99 contains a configuration injection vulnerability in the POST /api/cli-tools/hermes-settings endpoint that allows authenticated dashboard users to inject arbitrary keys into the Hermes Agent config.yaml file. Attackers can submit a baseUrl containing double quotes and newlines to add hooks_auto_accept and a hooks.post_llm_call shell command, which Hermes Agent executes without approval after an LLM call.
Published: 2026-10-10
Score: 7.3 High
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Patch
AI Analysis

Impact

A configuration injection flaw exists in the POST /api/cli-tools/hermes-settings endpoint of 9router. The bug allows a user who is authenticated to the dashboard to inject arbitrary keys into the Hermes Agent’s config.yaml file. By submitting a baseUrl containing double quotes and newlines, the attacker can add new configuration entries that trigger the Hermes Agent to execute a shell command via hooks.post_llm_call after an LLM call, providing remote code execution on the host where the Hermes Agent runs. This flaw is a classic case of code injection (CWE-94).

Affected Systems

The vulnerability affects decolua’s 9router in all releases from 0.4.1 through 0.5.99. No other vendors or products are listed as impacted.

Risk and Exploitability

The CVSS base score of 7.3 indicates a high level of risk. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog. The attack vector necessarily requires the attacker to be an authenticated dashboard user who can reach the /api/cli-tools/hermes-settings endpoint. Once that condition is met, the attacker can inject commands that will run with the privileges of the Hermes Agent process. Given the lack of client‐side filtering and the execution of arbitrary shell commands, the exploitation is straightforward for an authenticated user and can lead to full compromise of the node running the agent.

Generated by OpenCVE AI on October 10, 2026 at 19:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade 9router to the latest version where this endpoint is patched or the injection vulnerability is mitigated.
  • Restrict access to the /api/cli-tools/hermes-settings endpoint by firewalling or by enforcing stricter role‑based authentication so that only trusted administrators can use it.
  • Modify or remove the Hermes Agent config.yaml entries that allow dynamic hooks, such as disabling hooks_auto_accept and hooks.post_llm_call, to prevent unintended command execution.

Generated by OpenCVE AI on October 10, 2026 at 19:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 10 Oct 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Decolua
Decolua 9router
Vendors & Products Decolua
Decolua 9router

Sat, 10 Oct 2026 18:30:00 +0000

Type Values Removed Values Added
Description 9router 0.4.1 through 0.5.99 contains a configuration injection vulnerability in the POST /api/cli-tools/hermes-settings endpoint that allows authenticated dashboard users to inject arbitrary keys into the Hermes Agent config.yaml file. Attackers can submit a baseUrl containing double quotes and newlines to add hooks_auto_accept and a hooks.post_llm_call shell command, which Hermes Agent executes without approval after an LLM call.
Title 9router 0.4.1 through 0.5.99 Config Injection RCE via hermes-settings Endpoint
Weaknesses CWE-94
References
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 7.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-10T18:16:57.203Z

Reserved: 2026-10-10T18:08:11.797Z

Link: CVE-2026-108593

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-10T19:16:57.607

Modified: 2026-10-10T19:16:57.720

Link: CVE-2026-108593

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-10T19:30:17Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')