Impact
The vulnerability allows an attacker to manipulate the browser_snapshot function in Browser Tooling, enabling server‑side request forgery (SSRF). An exploited server can issue arbitrary HTTP requests, potentially accessing internal systems or sensitive data. This flaw is classified as CWE‑918, reflecting insufficient validation of request destinations.
Affected Systems
The affected product is NousResearch hermes‑agent, versions up to 0.16.0. The flaw resides in the tools/browser_tool.py component of the Browser Tooling module.
Risk and Exploitability
The CVSS score is 5.3, indicating moderate severity. EPSS is not available and the vulnerability is not listed in the CISA KEV catalog. The attack can be launched remotely, and the exploit has already been disclosed publicly, which may lead to opportunistic exploitation by threat actors.
OpenCVE Enrichment