Executive brief
NousResearch hermes-agent is an AI agent framework that connects large language models to messaging platforms like Telegram and Discord. A security flaw in its media handling component allows an attacker to trick the AI into reading and sending sensitive files from the host server. While the attack is limited to certain file types (like .csv, .pdf, or .zip), it can be used to steal database exports, backups, or private documents by bypassing the agent's normal security boundaries.
Technical details
A path traversal vulnerability exists in the `extract_media` function within `gateway/platforms/base.py`. The component uses a regular expression to identify `MEDIA:` tags in LLM responses but fails to perform directory containment or traversal checks on the resulting file paths. By using prompt injection, a remote attacker can force the agent to output a path like `MEDIA:/var/backups/data.zip`. The system then uses `os.path.expanduser()` and reads the file from the host filesystem to send as an attachment. While the exploit is restricted to files with specific extensions (e.g., .csv, .txt, .pdf, .zip, .docx), it bypasses the sandbox restrictions enforced in other modules like `file_tools.py`. As of the advisory date, the vendor has not responded to disclosure attempts.
Affected products
- NousResearch hermes-agent up to 2026.5.16
Timeline
- 2026-06-01: disclosed: Initial researcher report via GitHub Gist
- 2026-07-04: advisory: CVE published and added to NVD/VulDB