CPE
Hermes Agent versions prior to 0.19.0 contain a supply chain vulnerability where the bundled MCP catalog uses mutable branch references, enabling remote code execution if an upstream repository is compromised.