Impact
Hermes Agent versions older than 0.19.0 contain a supply‑chain flaw that allows a remote attacker to execute arbitrary code on a host during catalog installation. The vulnerability arises because the MCP catalog references an upstream repository by a mutable branch rather than a fixed commit SHA, violating immutability guarantees. This weakness, classified as CWE‑494, permits an attacker who compromises the upstream source to deliver malicious code to every system that pulls the affected catalog entry, resulting in full code execution on the target machine.
Affected Systems
The flaw affects deployments of NousResearch Hermes Agent 0.18.2 or earlier that rely on the MCP catalog entry pointing to a mutable branch. Users running these versions are susceptible, while version 0.19.0 and later no longer include the vulnerable catalog configuration.
Risk and Exploitability
The CVSS score of 9 indicates a high‑severity risk, and though no EPSS score is available and the vulnerability is not listed in the CISA KEV catalog, the attack requires only a compromise of the upstream repository—a task that can be executed with moderate effort by a motivated adversary. The exploit path is network‑based via the catalog download process, and once the upstream is subverted, the malicious code propagates automatically to all hosts that install the compromised catalog entry.
OpenCVE Enrichment