Executive brief
NousResearch hermes-agent is an AI agent framework that can integrate with platforms like Discord. A security flaw in its Discord integration allows unauthorized users to bypass authentication and gain full access to the agent's tools and data. This occurs if an attacker shares any other Discord server with the bot and possesses a role ID that matches the bot's restricted access configuration. An attacker could use this to execute commands, extract memory, or compromise connected infrastructure via direct messages.
Technical details
An improper authentication vulnerability (CWE-287) exists in the `DiscordAdapter._is_allowed_user` function within `gateway/platforms/discord.py`. The vulnerability is caused by an insecure fallback mechanism that scans all mutual guilds shared between the bot and a user when `DISCORD_ALLOWED_ROLES` is configured. If a user interacts with the bot via Direct Message (DM), the bot iterates through all servers it belongs to; if the user has a role ID in any of those servers that matches an entry in `DISCORD_ALLOWED_ROLES`, access is granted. This allows an attacker to bypass authentication by obtaining a matching role ID in a secondary, non-restricted server that the bot also inhabits. The vulnerability was reportedly remediated in commit `ef1e56557` by scoping role checks to the originating guild.
Affected products
- NousResearch hermes-agent <= 0.15.2
Timeline
- 2026-05-07: patched: Remediated in commit ef1e56557
- 2026-06-01: disclosed: Public disclosure via GitHub Gist
- 2026-07-04: advisory: NVD/VulDB publication