CVE-2026-82021

Source
https://cve.org/CVERecord?id=CVE-2026-82021
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-82021.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-82021
Published
2026-08-28T18:50:38.180Z
Modified
2026-08-30T03:48:29.724680874Z
Severity
  • 9.0 (Critical) CVSS_V4 - CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H CVSS Calculator
Summary
Hermes Agent 0.18.2 < 0.19.0 MCP Catalog Supply Chain RCE via Mutable Branch Reference
Details

Hermes Agent 0.18.2 prior to 0.19.0 contains a supply chain vulnerability in its bundled MCP catalog that allows a remote attacker to execute arbitrary code by compromising a third-party upstream repository referenced via a mutable branch rather than a pinned commit SHA. An attacker who compromises the upstream repository can propagate malicious code to every host that installs the affected catalog entry, with no further action required by the operator.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/82xxx/CVE-2026-82021.json",
    "unresolved_ranges": [
        {
            "source": "AFFECTED_FIELD",
            "extracted_events": [
                {
                    "introduced": "0.18.2"
                },
                {
                    "fixed": "0.19.0"
                }
            ]
        }
    ],
    "cwe_ids": [
        "CWE-494"
    ],
    "cna_assigner": "VulnCheck"
}
References

Affected packages

Git / github.com/nousresearch/hermes-agent

Affected ranges

Type
GIT
Repo
https://github.com/nousresearch/hermes-agent
Events
Database specific
Show details
{
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ],
    "extracted_events": [
        {
            "introduced": "2026.7.7.2"
        },
        {
            "fixed": "2026.7.20"
        }
    ]
}

Affected versions

v2026.*
v2026.7.7.2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-82021.json"