Executive brief
NousResearch hermes-agent, an AI agent framework, contains a security flaw in its SimpleX Gateway authorization component. An attacker can bypass the user allowlist by spoofing their profile display name to match a trusted user's name. This could allow unauthorized individuals to gain full access to the agent's capabilities and any data it manages.
Technical details
The vulnerability exists in the SimpleX platform adapter (hermes-agent/plugins/platforms/simplex/adapter.py) and the gateway authorization logic (_is_user_authorized in gateway/run.py). The system incorrectly validated users in the SIMPLEX_ALLOWED_USERS list against the 'source.user_name' field, which is a self-asserted, non-unique profile display name controlled by the remote user. An attacker can bypass the allowlist by changing their profile name to match a trusted user's name. The fix involves anchoring the authorization check to the 'localDisplayName' (a locally assigned, unique alias) or the numeric 'contactId', which cannot be forged by the remote party.
Affected products
- NousResearch hermes-agent 2026.6.5
Timeline
- 2026-07-25: advisory: NVD/VulDB publication date
- 2026-06-07: patched: Pull request with fix submitted to GitHub repository
References
- https://github.com/NousResearch/hermes-agent/
- https://github.com/NousResearch/hermes-agent/commit/490c486ff65b766d9de0fe0e6f26e1778aaa8fb3
- https://github.com/NousResearch/hermes-agent/issues/44729
- https://github.com/NousResearch/hermes-agent/issues/44730
- https://github.com/NousResearch/hermes-agent/pull/41246
- https://vuldb.com/cve/CVE-2026-17432
- https://vuldb.com/submit/862424