Junglewise Threat Intelligence

CVE-2026-53869: NousResearch Hermes Agent DNS rebinding in WebSocket endpoints

CVE-2026-53869 · Severity: high · CVSS 7.5 · Published 2026-06-17

Technologies: hermes-agent (PyPI), NousResearch Hermes Agent. Vendors: PyPI, NousResearch.

Executive brief

Hermes Agent, a tool used for managing AI agents and terminal sessions, contains a security flaw in its web dashboard. An attacker could use a technique called DNS rebinding to trick a user's browser into communicating with the agent's internal management interface. If successful, this could allow an attacker to inject malicious commands into the terminal or view sensitive output, potentially compromising the host system.

Technical details

A DNS rebinding vulnerability exists in the WebSocket endpoints of Hermes Agent's web dashboard. While the application implemented Host-header validation for standard HTTP requests via FastAPI middleware, this middleware does not execute for WebSocket upgrade requests. Consequently, the /api/pty, /api/ws, /api/pub, and /api/events endpoints failed to validate the Host and Origin headers. An attacker can exploit this by inducing a victim's browser to initiate a WebSocket connection to the local agent via a malicious domain. If a valid session token is present (e.g., via the query string), the attacker can bypass the intended loopback/host boundaries to interact with the terminal (PTY) or read event streams. This issue is resolved in version 0.16.0 (v2026.6.5).

Affected products

  • NousResearch hermes-agent < 0.16.0

Timeline

  • 2026-05-22: other: Initial fix PR submitted
  • 2026-05-24: patched: Fix merged into main branch
  • 2026-06-05: advisory: Release v0.16.0 published
  • 2026-06-17: disclosed: CVE published to NVD

References

Related threats