Impact
A flaw in the Session Chat Interface of NousResearch hermes‑agent allows a remote attacker to manipulate the file gateway/platforms/api_server.py module and trigger a denial of service. The vulnerability is identified as a failure to properly manage resources, leading to service unavailability for legitimate users. The impact is that the affected component can be exhausted and must be restarted, interrupting normal operation.
Affected Systems
The vulnerability is known to affect version 0.18.0 of NousResearch hermes‑agent. No other versions are currently listed as impacted.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. No EPSS score is available, and the issue is not in the CISA KEV catalog. The attack can be carried out remotely, and an exploit has already been published, implying the possibility of real‐world attacks. Because the vendor has not responded to disclosure, there is no official patch or workaround yet available.
OpenCVE Enrichment