<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Hermes-Agent (0.18.0) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/hermes-agent-0.18.0/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 03 Sep 2026 13:21:43 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/hermes-agent-0.18.0/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Authorization Bypass in NousResearch hermes-agent</title><link>https://feed.craftedsignal.io/briefs/2026-09-hermes-agent-auth-bypass/</link><pubDate>Thu, 03 Sep 2026 13:21:43 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-hermes-agent-auth-bypass/</guid><description>An authorization bypass vulnerability in the _sess_nowait function of NousResearch hermes-agent version 0.18.0 allows remote attackers to gain unauthorized access by manipulating the session_id argument.</description><content:encoded><![CDATA[<p>NousResearch hermes-agent version 0.18.0 contains a security flaw in the session management component, specifically within the _sess_nowait function located in s71.py. The vulnerability arises from improper validation of the session_id argument, which can be manipulated by a remote attacker to bypass authorization mechanisms. This vulnerability, tracked as CVE-2026-85105, enables unauthenticated actors to potentially hijack or interact with active sessions without valid credentials. The vendor has not responded to disclosure attempts, and no security updates are currently available to address this specific flaw. Organizations utilizing this version of hermes-agent in cloud or network-integrated environments should restrict access to the affected component to prevent unauthorized exploitation.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of this vulnerability leads to a complete authorization bypass, allowing attackers to perform actions as an authenticated user or administrative session. This poses a significant risk to data integrity and confidentiality for deployments relying on hermes-agent for session management. As the service is designed for remote interaction, the potential for widespread exploitation across internet-exposed instances is high if the affected endpoint is reachable.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Perform an inventory of all systems currently running NousResearch hermes-agent version 0.18.0.</li>
<li>Implement strict network-level access controls (ACLs) or VPN requirements to prevent unauthorized remote reachability to the vulnerable session management endpoints.</li>
<li>Monitor logs for unusual session activity or repeated attempts to access endpoints with manipulated session identifiers.</li>
<li>If a patch or update is released, prioritize its deployment immediately due to the high severity of the authorization bypass.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item></channel></rss>