Junglewise Threat Intelligence

CVE-2026-84289: NousResearch hermes-agent denial of service in MCP Tool

CVE-2026-84289 · Severity: medium · CVSS 4.3 · Published 2026-09-01

Technologies: NousResearch Hermes Agent. Vendors: NousResearch.

Executive brief

Hermes Agent is an AI agent framework that processes tool definitions and resource constraints. A flaw in how it handles MCP Tool resource boundaries allows an attacker to trigger uncontrolled memory allocation, causing the service to become unresponsive or crash. An attacker can exploit this remotely without authentication.

Technical details

The vulnerability exists in the list_tools function of tools/mcp_tool.py within the MCP Tool component of Hermes Agent. The root cause is missing validation of MCP resource boundaries, allowing an attacker to craft malicious input that triggers uncontrolled memory allocation and resource exhaustion. The attack is network-accessible and does not require authentication or user interaction. Exploitation results in a denial of service (DoS) condition, making the agent unavailable. The vendor was contacted prior to public disclosure but did not respond; patches are not currently available.

Affected products

  • NousResearch hermes-agent up to 0.18.2

Timeline

  • 2026-09-01: disclosed: Vulnerability disclosed publicly; vendor previously contacted but did not respond
  • 2026-09-01: other: Exploit code made public

References

Related threats