Impact
Incomplete case-sensitive handling within the _filter_and_accumulate method of the Streaming Reasoning Tag Filter component allows a caller to supply tags that are not properly validated, effectively bypassing the intended filtering logic. The issue is classified as CWE-178, "Improper Case Conversion", and is also associated with CWE-697, "Incorrect Keystroke Timing or Sequence". The description indicates that remote actors can trigger the flaw; the complexity is high and the exploitability is considered difficult. The project has elected not to provide a dedicated fix, citing maintenance cost concerns.
Affected Systems
All deployments of NousResearch Hermes Agent that include the gateway/stream_consumer.py to and including 2026.4.30 are affected.
Risk and Exploitability
The reported CVSS score of 2.3 reflects a low severity rating. The EPSS score is reported as less than 1%, indicating a very low probability of real-world exploitation. The vulnerability can be initiated remotely but requires high effort and hard-to-reproduce conditions, and the vulnerability is not listed in the CISA KEV catalog. Consequently, the likelihood of active attacks is low, yet the impact of a bypass could be significant if the filtering is relied upon for policy enforcement.
OpenCVE Enrichment