Executive brief
NousResearch hermes-agent is an AI agent framework used for building autonomous systems. A denial-of-service vulnerability in the ACP (Agent Communication Protocol) Prompt Workflow component allows remote attackers to cause service unavailability, disrupting the availability of applications built with this library.
Technical details
A denial-of-service vulnerability exists in the HermesACPAgent.prompt function within acp_adapter/session.py of the ACP Prompt Workflow component. The vulnerability allows remote attackers to trigger a denial-of-service condition through improper handling of queued prompts. No authentication is required, and the attack is network-accessible. The vulnerability has been publicly disclosed with proof-of-concept code available, though the vendor did not respond to early notification attempts. Patches or vendor updates have not been confirmed.
Affected products
- NousResearch hermes-agent up to 0.18.2
Timeline
- 2026-09-01: disclosed: Public disclosure with proof-of-concept code