Executive brief
NousResearch hermes-agent is a tool used to give AI agents the ability to interact with local files. A security flaw allows remote users to bypass safety checks and force the agent to read restricted system device files. This can cause the agent to hang indefinitely, leading to a denial of service that prevents other users from accessing the system.
Technical details
A path traversal vulnerability exists in the `_is_blocked_device` function within `tools/file_tools.py` of NousResearch hermes-agent. The function attempts to block access to dangerous device files (like /dev/zero) using `os.path.expanduser()` for normalization, which fails to resolve standard UNIX path sequences like './' or '../'. An attacker can bypass the blocklist by providing a path such as '/dev/./zero', causing the agent to enter an infinite read loop when the OS resolves the path. This results in a process hang or thread exhaustion, particularly impactful in gateway deployments (e.g., Discord or Telegram bots). As of the advisory date, the vendor has not responded to the disclosure.
Affected products
- NousResearch hermes-agent <= 2026.4.16
Timeline
- 2026-04-24: disclosed: Initial discovery and public Gist disclosure
- 2026-05-24: advisory: CVE published to NVD