Impact
The vulnerability resides in the fetchLinkTitle function within the Link Title Fetch component of NousResearch's hermes‑agent. By manipulating the URL parameter, an attacker can cause the server to issue HTTP requests to arbitrary destinations. This behavior enables a server-side request forgery attack that could expose internal network resources, bypass authentication, or exfiltrate data. The weakness is a classic SSRF flaw (CWE‑918).
Affected Systems
The flaw affects the 0.18.0 release of NousResearch's hermes‑agent. Administrators of this version should identify installations of hermes‑agent where the Link Title Fetch feature is enabled, as the vulnerable function is part of the desktop application artifact component.
Risk and Exploitability
The CVSS score of 5.3 indicates a medium severity risk. The EPSS score is not available, and the vulnerability is not currently listed in the CISA KEV catalog. An attacker can launch the exploit remotely by supplying a crafted URL without requiring authentication, making it a straightforward SSRF attack. While the impact is limited to the agent’s outbound network reach, it still poses a significant threat to internal infrastructure.
OpenCVE Enrichment