Executive brief
A vulnerability exists in hermes-agent, an AI agent framework, that allows attackers to hijack the agent's behavior. By planting malicious text within a "todo" list item, an attacker can force the AI to ignore its original safety instructions and perform unauthorized actions, such as stealing sensitive data or abusing connected tools, once the agent's memory reaches a certain limit. This occurs because the system fails to distinguish between administrative task lists and direct user commands during its memory cleanup process.
Technical details
A prompt injection vulnerability exists in the `_compress_context` method of `run_agent.py` in hermes-agent versions up to 0.19.0. When the agent's context window overflows, the system triggers a compression routine that preserves active tasks by calling `TodoStore.format_for_injection()`. This function concatenates raw, unsanitized todo item content into a string that is then appended to the message history as a `{"role": "user"}` message. Because instruction-tuned LLMs prioritize the most recent user message, an attacker can plant a payload in a todo item (either directly or indirectly via malicious documents the agent reads) that overrides system prompts, leading to unauthorized tool execution or data exfiltration. A patch was committed (2ca38e5) but advisories indicate versions up to 0.19.0 may remain affected.
Affected products
- NousResearch hermes-agent <= 0.19.0
Timeline
- 2026-05-07: disclosed: Initial PoC and report created by researcher YLChen-007
- 2026-06-01: advisory: GitHub Advisory and NVD entry published