Description
A security flaw has been discovered in NousResearch hermes-agent 2026.4.23. Affected is the function _discover_dashboard_plugins of the file hermes_cli/web_server.py of the component CLI web-dashboard Interface. Performing a manipulation of the argument HERMES_ENABLE_PROJECT_PLUGINS results in incorrect comparison. The attack is only possible with local access. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-05-24
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw lies in the _discover_dashboard_plugins function of hermes_cli/web_server.py; a manipulated HERMES_ENABLE_PROJECT_PLUGINS argument triggers an incorrect comparison, potentially allowing an attacker to enable plugins that should be disabled. This miscomparison can lead to unauthorized code execution or privilege escalation on the local host, as the affected system can load and run malicious plugins. The vulnerability relies on local access to affect the environment, and its exploitation requires the attacker already have a foothold on the target machine.

Affected Systems

The vulnerability affects NousResearch Hermes Agent version 2026.4.23 in the CLI web-dashboard component. No other versions or products are listed as affected.

Risk and Exploitability

The CVSS score of 4.8 indicates a moderate severity. The EPSS score is not available, but the exploit has already been released publicly, suggesting that a determined attacker could use it. The issue is not listed in the CISA KEV catalog, but because the flaw requires local access and the vendor has not responded, the risk remains significant for systems that have not yet applied a patch or update.

Generated by OpenCVE AI on May 24, 2026 at 10:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Hermes Agent to the latest version that contains the fix for the _discover_dashboard_plugins comparison issue
  • If an urgent patch is unavailable, configure the system to disable or tightly lock the HERMES_ENABLE_PROJECT_PLUGINS option, ensuring only trusted plugins are loaded
  • Regularly audit the list of enabled plugins and monitor for any unexpected changes to the plugin configuration

Generated by OpenCVE AI on May 24, 2026 at 10:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 24 May 2026 09:15:00 +0000

Type Values Removed Values Added
Description A security flaw has been discovered in NousResearch hermes-agent 2026.4.23. Affected is the function _discover_dashboard_plugins of the file hermes_cli/web_server.py of the component CLI web-dashboard Interface. Performing a manipulation of the argument HERMES_ENABLE_PROJECT_PLUGINS results in incorrect comparison. The attack is only possible with local access. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Title NousResearch hermes-agent CLI web-dashboard web_server.py _discover_dashboard_plugins comparison
First Time appeared Nousresearch
Nousresearch hermes-agent
Weaknesses CWE-697
CPEs cpe:2.3:a:nousresearch:hermes-agent:*:*:*:*:*:*:*:*
Vendors & Products Nousresearch
Nousresearch hermes-agent
References
Metrics cvssV2_0

{'score': 4.3, 'vector': 'AV:L/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 5.3, 'vector': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Nousresearch Hermes-agent
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-05-24T09:00:16.979Z

Reserved: 2026-05-23T10:33:18.362Z

Link: CVE-2026-9369

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-24T10:30:15Z

Weaknesses