Impact
A vulnerability exists in the HermesACPAgent.prompt function of the ACP Prompt Workflow in NousResearch hermes-agent versions up to 0.18.2. The flaw allows an attacker to manipulate the input in such a way that the HermesACPAgent.prompt method fails or crashes, resulting in a denial of service. The attack may be performed from remote, and the exploit has been publicly disclosed. The weakness is classified as CWE‑404, indicating improper removal or cleanup leading to denial of service.
Affected Systems
Affected systems are the NousResearch hermes-agent product, specifically versions up to and including 0.18.2. The vulnerability is tied to the ACP Prompt Workflow component in the file acp_adapter/session.py. No other product versions are listed, so the impact is confined to this agent version range.
Risk and Exploitability
The CVSS base score of 5.3 indicates a medium severity negotiating with exploitation likelihood. EPSS data is not available, so the likelihood of exploitation in the wild is uncertain. The vulnerability is not listed in CISA KEV, suggesting no known widespread exploitation. Attackers can send crafted requests remotely through the HermesACPAgent.prompt endpoint, causing the service to crash or hang and potentially overwhelming system resources. A proper mitigation strategy is to update to a fixed version as soon as it becomes available and consider network isolation of that API until the patch is installed.
OpenCVE Enrichment