Executive brief
A security flaw in the NousResearch Hermes Agent allows unauthorized users to access and take over other people's chat sessions. By simply guessing or knowing the title of a conversation, an attacker can gain full access to the chat history, including any private information or API keys shared with the AI agent. This affects multi-user deployments like Discord or Telegram bots where multiple people share the same backend system.
Technical details
The vulnerability exists in the `resolve_session_by_title` and `get_session_by_title` functions within `hermes_state.py`. These functions perform global SQL queries against the session database without filtering by `user_id` or `source` platform. An attacker can invoke the `/resume` command with a target session's title to redirect their active session pointer to a victim's session. This grants the attacker full read/write access to the victim's conversation history and the ability to execute commands in the victim's context. The issue is present in versions up to 0.12.0 (specifically tag v2026.4.30) and currently has no official patch.
Affected products
- NousResearch hermes-agent <= 0.12.0
Timeline
- 2026-05-07: disclosed: Vulnerability discovered and PoC created by researcher YLChen-007
- 2026-06-07: advisory: CVE-2026-11461 published via VulDB/NVD