Supply Chain Vulnerability in Hermes Agent by Nous Research
CVE-2026-82021
9CRITICAL
What is CVE-2026-82021?
Hermes Agent versions prior to 0.19.0 contain a supply chain vulnerability in its MCP catalog. This issue allows a remote attacker to execute arbitrary code through a compromised third-party upstream repository. By utilizing a mutable branch reference instead of a secured commit SHA, the vulnerability exposes all installations of the affected catalog entry to potential malicious code, thereby enabling an attacker to propagate harmful modifications without any additional intervention from the user.
Affected Version(s)
hermes-agent 0.18.2
hermes-agent 0.18.2 < 0.19.0
hermes-agent 2026.7.7.2 < 2026.7.20
