Impact
The Hermes-agent MCP Tool contains a flaw in the list_tools function that allows an attacker to supply input that triggers uncontrolled memory allocation, potentially exhausting system resources and causing a denial of service. This results in degraded availability for any process relying on the agent and may impact overall system stability.
Affected Systems
The vulnerability affects all NousResearch Hermes-agent deployments on or before version 0.18.2. Any instance running a vulnerable version is subject to risk until an updated release is applied.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The exploit is remote and publicly documented, and no EPSS data is available, but the lack of a KEV listing suggests a lower observed exploitation rate. An attacker can trigger the vulnerability by sending crafted requests to the MCP tool over the network, leading to resource exhaustion and service interruption.
OpenCVE Enrichment