{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3ahermeshermes_agent/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:hermes:hermes_agent:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.3,"id":"CVE-2026-82021"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Hermes Agent (\u003c 0.19.0)"],"_cs_severities":["high"],"_cs_tags":["supply-chain","rce","vulnerability"],"_cs_type":"advisory","_cs_vendors":["Hermes"],"content_html":"\u003cp\u003eHermes Agent versions 0.18.2 and earlier are susceptible to a supply chain attack involving the agent's bundled MCP catalog. The configuration relies on mutable branch names to fetch dependencies from upstream repositories rather than using pinned commit SHAs. This design choice creates a window of opportunity for attackers who compromise an upstream repository to inject malicious payloads directly into the catalog. When the Hermes Agent performs its update or installation sequence, it automatically pulls and executes the compromised code. Because this process occurs without user interaction or signature validation, the compromise can silently propagate to any host utilizing the affected catalog entry. This vulnerability poses a significant risk to environment integrity, as it facilitates remote code execution at the execution privilege level of the Hermes Agent service.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability allows an attacker to achieve remote code execution on any system running affected versions of Hermes Agent. By compromising an upstream dependency, the attacker gains the ability to execute arbitrary commands across the entire estate that consumes the affected catalog. This could lead to full system compromise, exfiltration of sensitive configuration data, or lateral movement within the affected network.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade all instances of Hermes Agent to version 0.19.0 or later immediately to resolve the dependency management issue.\u003c/li\u003e\n\u003cli\u003eAudit all local MCP catalog configurations to identify and manually pin any mutable branch references to specific, verified commit SHAs until upgrades are complete.\u003c/li\u003e\n\u003cli\u003eImplement egress filtering for systems running Hermes Agent to restrict connections only to trusted, known-good repository domains, limiting the attacker's ability to pull malicious payloads from rogue infrastructure.\u003c/li\u003e\n\u003cli\u003eMonitor for unauthorized modifications to local MCP catalog files or unexpected network activity from the Hermes Agent process originating from package distribution sources.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-28T21:37:54Z","date_published":"2026-08-28T21:37:54Z","id":"https://feed.craftedsignal.io/briefs/2026-08-hermes-agent-supply-chain/","summary":"Hermes Agent versions prior to 0.19.0 contain a supply chain vulnerability where the bundled MCP catalog uses mutable branch references, enabling remote code execution if an upstream repository is compromised.","title":"Hermes Agent Supply Chain Vulnerability via Mutable MCP Catalog References","url":"https://feed.craftedsignal.io/briefs/2026-08-hermes-agent-supply-chain/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:hermes:hermes_agent:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}