Executive brief
NousResearch hermes-agent is an AI agent framework that integrates with xAI's image generation service. The framework's image generation tool contains a flaw that allows the xAI provider to inject arbitrary URLs which the Hermes host then fetches without validation. An attacker controlling or compromising the image provider could force the Hermes server to make requests to internal services, cloud metadata endpoints, or loopback services, potentially exposing sensitive information accessible from the server's network context.
Technical details
The vulnerability is a server-side request forgery (SSRF) in the image_gen_provider.py component, specifically in the save_url_image() function. When the xAI image generation provider returns image data with a URL field (data[0].url), the hermes-agent framework fetches this URL directly using requests.get() without invoking the existing URL safety checks (is_safe_url) or redirect validation. The attack vector is network-based and requires the attacker to control or compromise the configured xAI image provider or intercept its response. A malicious provider can return attacker-controlled URLs that the Hermes process will fetch from its host, exposing loopback services, internal HTTP endpoints, or cloud metadata targets. The vendor was contacted early but did not respond; a working proof-of-concept and exploit code have been published.
Affected products
- NousResearch hermes-agent up to 0.16.0
Timeline
- 2026-08-04: disclosed
- 2026-06-12: other: Exploit published on GitHub Gist