Resource Allocation Vulnerability in NousResearch Hermes-Agent
CVE-2026-85107
5.3MEDIUM
What is CVE-2026-85107?
A vulnerability exists in the NousResearch hermes-agent 0.18.0, impacting the resourceBufferFromUrl function within the Electron Main Process. This flaw can be exploited, allowing remote manipulation that leads to unregulated allocation of system resources. Notably, the copyImageFromUrl() function, previously reachable in version v2026.8.3, was removed in v2026.8.19, making the modern alternative, event.sender.copyImageAt(), the current method for image copying within the Electron framework.
Affected Version(s)
hermes-agent 0.18.0
References
CVSS V4
Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
Vulnerability published
Vulnerability Reserved
Credit
KendrickZou (VulDB User)
VulDB Vulnerability Moderation Team
