Junglewise Threat Intelligence

CVE-2026-84288: NousResearch hermes-agent denial of service in ACP Prompt Workflow

CVE-2026-84288 · Severity: medium · CVSS 4.3 · Published 2026-09-01

Technologies: NousResearch Hermes Agent. Vendors: NousResearch.

Executive brief

NousResearch hermes-agent is an AI agent framework used for building autonomous systems. A denial-of-service vulnerability in the ACP (Agent Communication Protocol) Prompt Workflow component allows remote attackers to cause service unavailability, disrupting the availability of applications built with this library.

Technical details

A denial-of-service vulnerability exists in the HermesACPAgent.prompt function within acp_adapter/session.py of the ACP Prompt Workflow component. The vulnerability allows remote attackers to trigger a denial-of-service condition through improper handling of queued prompts. No authentication is required, and the attack is network-accessible. The vulnerability has been publicly disclosed with proof-of-concept code available, though the vendor did not respond to early notification attempts. Patches or vendor updates have not been confirmed.

Affected products

  • NousResearch hermes-agent up to 0.18.2

Timeline

  • 2026-09-01: disclosed: Public disclosure with proof-of-concept code

References

Related threats