Impact
A weakness in the HTTP API of NousResearch hermes-agent allows a remote attacker to manipulate the 'todos' argument of the AIAgent.run_conversation function in run_agent.py. The manipulation causes excessive resource consumption, leading the service to become unresponsive and resulting in a denial of service (CWE‑404). The flaw does not reveal or alter data and does not provide privilege escalation or remote code execution.
Affected Systems
NousResearch hermes 2026.4.30 are affected. The vulnerability resides in the HTTP API component of the product Hermès‑Agent delivered by NousResearch.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate risk, while the EPSS score of <1% suggests a very low but nonzero exploitation probability. It is not listed in the CISA KEV catalog, yet a public exploit is available and can be triggered remotely via API traffic, leading to service interruption without data compromise.
OpenCVE Enrichment