Improper Authentication in NousResearch hermes-agent API Component
CVE-2026-7112
Key Information:
- Vendor
Nousresearch
- Status
- Vendor
- CVE Published:
- 27 April 2026
Badges
What is CVE-2026-7112?
A security flaw exists in the NousResearch hermes-agent version 0.8.0 involving the function _check_auth located in the file gateway/platforms/api_server.py. This vulnerability allows for improper authentication, potentially enabling remote attackers to manipulate user access and permissions. Although the complexity of the attack is noted as high, the exploitation remains a public concern due to the disclosure of the exploit details. Early notification was provided to the project through a pull request, yet no corrective action has been implemented.
Affected Version(s)
hermes-agent 0.8.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
