<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:hermes:hermes_agent:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3ahermeshermes_agent/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 28 Aug 2026 21:37:54 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3ahermeshermes_agent/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Hermes Agent Supply Chain Vulnerability via Mutable MCP Catalog References</title><link>https://feed.craftedsignal.io/briefs/2026-08-hermes-agent-supply-chain/</link><pubDate>Fri, 28 Aug 2026 21:37:54 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-hermes-agent-supply-chain/</guid><description>Hermes Agent versions prior to 0.19.0 contain a supply chain vulnerability where the bundled MCP catalog uses mutable branch references, enabling remote code execution if an upstream repository is compromised.</description><content:encoded><![CDATA[<p>Hermes Agent versions 0.18.2 and earlier are susceptible to a supply chain attack involving the agent's bundled MCP catalog. The configuration relies on mutable branch names to fetch dependencies from upstream repositories rather than using pinned commit SHAs. This design choice creates a window of opportunity for attackers who compromise an upstream repository to inject malicious payloads directly into the catalog. When the Hermes Agent performs its update or installation sequence, it automatically pulls and executes the compromised code. Because this process occurs without user interaction or signature validation, the compromise can silently propagate to any host utilizing the affected catalog entry. This vulnerability poses a significant risk to environment integrity, as it facilitates remote code execution at the execution privilege level of the Hermes Agent service.</p>
<h2 id="impact">Impact</h2>
<p>The vulnerability allows an attacker to achieve remote code execution on any system running affected versions of Hermes Agent. By compromising an upstream dependency, the attacker gains the ability to execute arbitrary commands across the entire estate that consumes the affected catalog. This could lead to full system compromise, exfiltration of sensitive configuration data, or lateral movement within the affected network.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade all instances of Hermes Agent to version 0.19.0 or later immediately to resolve the dependency management issue.</li>
<li>Audit all local MCP catalog configurations to identify and manually pin any mutable branch references to specific, verified commit SHAs until upgrades are complete.</li>
<li>Implement egress filtering for systems running Hermes Agent to restrict connections only to trusted, known-good repository domains, limiting the attacker's ability to pull malicious payloads from rogue infrastructure.</li>
<li>Monitor for unauthorized modifications to local MCP catalog files or unexpected network activity from the Hermes Agent process originating from package distribution sources.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>supply-chain</category><category>rce</category><category>vulnerability</category></item></channel></rss>