Impact
A configuration injection flaw exists in the POST /api/cli-tools/hermes-settings endpoint of 9router. The bug allows a user who is authenticated to the dashboard to inject arbitrary keys into the Hermes Agent’s config.yaml file. By submitting a baseUrl containing double quotes and newlines, the attacker can add new configuration entries that trigger the Hermes Agent to execute a shell command via hooks.post_llm_call after an LLM call, providing remote code execution on the host where the Hermes Agent runs. This flaw is a classic case of code injection (CWE-94).
Affected Systems
The vulnerability affects decolua’s 9router in all releases from 0.4.1 through 0.5.99. No other vendors or products are listed as impacted.
Risk and Exploitability
The CVSS base score of 7.3 indicates a high level of risk. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog. The attack vector necessarily requires the attacker to be an authenticated dashboard user who can reach the /api/cli-tools/hermes-settings endpoint. Once that condition is met, the attacker can inject commands that will run with the privileges of the Hermes Agent process. Given the lack of client‐side filtering and the execution of arbitrary shell commands, the exploitation is straightforward for an authenticated user and can lead to full compromise of the node running the agent.
OpenCVE Enrichment