PYSEC-2026-3575

See a problem?
Import Source
https://github.com/pypa/advisory-database/blob/main/vulns/hermes-agent/PYSEC-2026-3575.yaml
JSON Data
https://api.osv.dev/v1/vulns/PYSEC-2026-3575
Aliases
Published
2026-08-04T11:34:40.934032Z
Modified
2026-08-04T14:30:16.465346305Z
Severity
  • 6.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L CVSS Calculator
  • 2.1 (Low) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
hermes-agent has an Injection issue
Details

A weakness has been identified in NousResearch hermes-agent up to 2026.4.30. This affects the function scanmemorycontent of the file tools/memorytool.py. This manipulation causes injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

References

Affected packages

PyPI / hermes-agent

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.15.0

Affected versions

0.*
0.13.0
0.14.0

Database specific

source
"https://github.com/pypa/advisory-database/blob/main/vulns/hermes-agent/PYSEC-2026-3575.yaml"