{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/hermes-agent-0.18.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:nousresearch:hermes-agent:0.18.0:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-85105"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["hermes-agent (0.18.0)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["NousResearch"],"content_html":"\u003cp\u003eNousResearch hermes-agent version 0.18.0 contains a security flaw in the session management component, specifically within the _sess_nowait function located in s71.py. The vulnerability arises from improper validation of the session_id argument, which can be manipulated by a remote attacker to bypass authorization mechanisms. This vulnerability, tracked as CVE-2026-85105, enables unauthenticated actors to potentially hijack or interact with active sessions without valid credentials. The vendor has not responded to disclosure attempts, and no security updates are currently available to address this specific flaw. Organizations utilizing this version of hermes-agent in cloud or network-integrated environments should restrict access to the affected component to prevent unauthorized exploitation.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability leads to a complete authorization bypass, allowing attackers to perform actions as an authenticated user or administrative session. This poses a significant risk to data integrity and confidentiality for deployments relying on hermes-agent for session management. As the service is designed for remote interaction, the potential for widespread exploitation across internet-exposed instances is high if the affected endpoint is reachable.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePerform an inventory of all systems currently running NousResearch hermes-agent version 0.18.0.\u003c/li\u003e\n\u003cli\u003eImplement strict network-level access controls (ACLs) or VPN requirements to prevent unauthorized remote reachability to the vulnerable session management endpoints.\u003c/li\u003e\n\u003cli\u003eMonitor logs for unusual session activity or repeated attempts to access endpoints with manipulated session identifiers.\u003c/li\u003e\n\u003cli\u003eIf a patch or update is released, prioritize its deployment immediately due to the high severity of the authorization bypass.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-03T13:21:43Z","date_published":"2026-09-03T13:21:43Z","id":"https://feed.craftedsignal.io/briefs/2026-09-hermes-agent-auth-bypass/","summary":"An authorization bypass vulnerability in the _sess_nowait function of NousResearch hermes-agent version 0.18.0 allows remote attackers to gain unauthorized access by manipulating the session_id argument.","title":"Authorization Bypass in NousResearch hermes-agent","url":"https://feed.craftedsignal.io/briefs/2026-09-hermes-agent-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Hermes-Agent (0.18.0)","version":"https://jsonfeed.org/version/1.1"}