Impact
A flaw in the extract_media function of the Live Webhook Endpoint allows an attacker to supply a crafted request that triggers a path traversal condition. The vulnerability does not explicitly state that arbitrary file read or write is possible; it is inferred that the traversal could permit access to files outside the intended directory, but no documented exploitation of full system compromise is provided. The potential impact is limited to accessing or manipulating files within the server’s file system that lie outside the intended sandboxed directory.
Affected Systems
NousResearch Hermes Agent up to and including version 2026.5.16 are affected. Any deployments that expose the Live Webhook Endpoint to external traffic are at risk. Systems running later versions are presumed to be unaffected unless the vulnerability remains present in subsequent releases.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity, while the EPSS score of less than 1% shows a very low but non‑zero exploitation probability. The vulnerability is not listed in the CISA KEV catalog. The attack can be carried out remotely by sending extract_media routine without proper path sanitization. Failure to mitigate could allow an attacker to potentially read or modify files outside the intended directory.
OpenCVE Enrichment