Impact
A malicious .git/config file can inject an arbitrary operating‑system command via the git core.fsmonitor configuration. When the Hermes Agent refreshes the git index (for example after a user sends a message), the injected command is executed within the agent’s process, giving the attacker full access to the environment, including provider API keys. This results in a complete compromise of confidentiality, integrity and availability for any system running the vulnerable agent.
Affected Systems
Hermes Agent versions 0.18.2 through 0.21.0 owned by the NousResearch:hermes-agent product are susceptible. No other product or vendor is listed as affected.
Risk and Exploitability
The CVSS score of 8.6 marks this as a high‑severity vulnerability. EPSS is currently unavailable, and the exploit is not listed in the CISA KEV catalog. An attacker can succeed by providing a crafted repository; the culprit must be able to open the repository or otherwise trigger a git status refresh. Once the configuration is injected, the agent will execute the command in the user’s context, exposing the environment and any stored credentials.
OpenCVE Enrichment