Impact
A flaw in the resourceBufferFromUrl function of NousResearch hermes‑agent version 0.18.0 allows a remote actor to supply crafted requests that trigger unlimited resource allocation. The omission of bounds checking means the application can consume excessive memory or other system resources, potentially causing slowdown or crash. This type of weakness is identified as CWE‑400 and CWE‑770.
Affected Systems
The affected product is NousResearch hermes‑agent, version 0.18.0. Earlier releases before v2026.8.19 also had the copyImageFromUrl entry point, but newer versions use Electron‑native event.sender.copyImageAt().
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity, and the EPSS score is not available. The vulnerability is listed as not part of CISA’s KEV catalog. The attack can be started remotely by directing the application to process a malicious URL or payload, but no publicly known exploit is documented. Consequently, the risk is moderate, yet it could lead to denial of service if an attacker repeatedly triggers the allocation behavior.
OpenCVE Enrichment