Impact
The Hermes‑Agent service contains a path traversal flaw in the skill_view function When an attacker manipulates the Name argument, the application resolves file paths outside the intended directory. This can allow an attacker to read files that are not supposed to be exposed through the API. The vulnerability does not grant code execution or other elevated privileges; it primarily enables unauthorized file access.
Affected Systems
The affected product is NousResearch Hermes‑Agent, version 2026.5.29.2. No other releases are documented as vulnerable.
Risk and Exploitability
The CVSS base score of 5.3 indicates moderate severity, while the EPSS signals a low probability of exploitation. The vulnerability is not listed in CISA's KEV catalog. It can be launched remotely, and a public exploit exists, making it a realistic risk for exposed instances. An attacker who can exploit the flaw would be able to access arbitrary files outside the allowed directory, potentially revealing sensitive configuration or data.
OpenCVE Enrichment