Memory Allocation Vulnerability in NousResearch Hermes-Agent MCP Tool
CVE-2026-84289
Key Information:
- Vendor
Nousresearch
- Status
- Vendor
- CVE Published:
- 1 September 2026
Badges
What is CVE-2026-84289?
A vulnerability has been identified in the NousResearch hermes-agent, specifically within the MCP Tool component (file: tools/mcp_tool.py). This vulnerability concerns the list_tools function, which is susceptible to uncontrolled memory allocation. The exploitation of this vulnerability may allow an attacker to perform a remote attack, leading to potential denial of service. The exploit details have been released publicly, and the vendor has not responded to initial disclosures regarding this issue.
Affected Version(s)
hermes-agent 0.18.0
hermes-agent 0.18.1
hermes-agent 0.18.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
