Impact
The flaw in the _check_slash_access function of the Quick Command Handler causes incorrect authorization checks. Attackers can remotely exploit this to gain unauthorized access to restricted operations. This results in potential confidentiality and integrity risks if malicious commands can be executed with the agent’s privileges. The issue is rooted in authorization and path validation weaknesses.
Affected Systems
The affected product is NousResearch hermes-agent, with vulnerability present in all releases up to version 2026.6.5.
Risk and Exploitability
The CVSS score of 5.3 indicates medium severity. No EPSS data is available, so the likelihood cannot be quantified precisely, but the flaw is publicly exploitable and can be launched remotely from external networks. It is not listed in the CISA KEV catalog. An attacker can bypass authorization checks, enabling use of the Quick Command Handler with the privileges of the running agent process.
OpenCVE Enrichment