Supply Chain Vulnerability in Hermes Agent by Nous Research
CVE-2026-82021

9CRITICAL

Key Information:

Vendor
CVE Published:
28 August 2026

What is CVE-2026-82021?

Hermes Agent versions prior to 0.19.0 contain a supply chain vulnerability in its MCP catalog. This issue allows a remote attacker to execute arbitrary code through a compromised third-party upstream repository. By utilizing a mutable branch reference instead of a secured commit SHA, the vulnerability exposes all installations of the affected catalog entry to potential malicious code, thereby enabling an attacker to propagate harmful modifications without any additional intervention from the user.

Affected Version(s)

hermes-agent 0.18.2

hermes-agent 0.18.2 < 0.19.0

hermes-agent 2026.7.7.2 < 2026.7.20

References

CVSS V4

Score:
9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Zubair Ashraf (@zashraf1337)
.