Vendor
high
advisory
Hermes Agent Supply Chain Vulnerability via Mutable MCP Catalog References
1 TTP 1 CVEHermes Agent versions prior to 0.19.0 contain a supply chain vulnerability where the bundled MCP catalog uses mutable branch references, enabling remote code execution if an upstream repository is compromised.
Hermes Agent
supply-chain
rce
vulnerability
1t
1c
critical
advisory
CVE-2026-58122: Hermes WebUI Authentication Bypass via Spoofed X-Forwarded-For Header
1 rule 4 TTPs 1 CVECVE-2026-58122 describes an authentication bypass vulnerability in Hermes WebUI before version 0.51.307, allowing unauthenticated remote attackers to bypass local-origin IP restrictions on onboarding endpoints by spoofing the X-Forwarded-For header with a loopback address, leading to server-side request forgery (SSRF), API key overwrites, and persistent access token acquisition.
Hermes WebUI < 0.51.307
authentication-bypass
ssrf
web-vulnerability
credential-theft
persistence
cloud
network
1r
4t
1c