Executive brief
NousResearch hermes-agent is an AI agent library used for building conversational applications. A flaw in the Session Chat Interface component allows remote attackers to cause a denial of service, disrupting availability of applications built on this library without requiring authentication.
Technical details
A denial of service vulnerability exists in hermes-agent 0.18.0 within the Session Chat Interface component, specifically in the gateway/platforms/api_server.py file. The vulnerability is remotely exploitable without authentication. An attacker can leverage this flaw to trigger a denial of service condition, impacting application availability. A public exploit is available, and the vendor did not respond to early disclosure attempts.
Affected products
- NousResearch hermes-agent 0.18.0
Timeline
- 2026-09-01: disclosed