Impact
The vulnerability is an improper path restriction flaw that permits malicious actors to overwrite the credential store by bypassing safeguards that normally protect the auth.json file. This oversight can lead to unauthorized credential tampering and potentially allow attackers to gain or elevate access to the system. The weakness is classified as CWE-552, which concerns unauthorized read or modification of data through improper path handling.
Affected Systems
The affected product is the Hermes Agent developed by Nous Research. Versions from 0.16.0 up to, but not including, 0.17.0 are vulnerable. This includes all 0.16.x releases that precede the 0.17.0 release.
Risk and Exploitability
The CVSS score of 7.6 indicates a high severity vulnerability. Although EPSS data is unavailable and the vulnerability is not listed in CISA's KEV, the attackers must be able to influence the content of messages ingested by the agent. Based on the description, the distant attack vector is inferred to be remote or from any source that can submit messages to the agent, bypassing path checks and overwriting the credential store, thereby causing credential compromise.
OpenCVE Enrichment