Executive brief
NousResearch hermes-agent is an AI-driven tool that allows autonomous agents to execute system commands. A security flaw in its command filtering system allows malicious actors to bypass safety checks and execute unauthorized commands on the underlying system. This could lead to a complete system takeover or unauthorized data access if the agent processes a maliciously crafted prompt.
Technical details
An OS command injection vulnerability exists in the `detect_dangerous_command` function within `tools/approval.py` of the NousResearch hermes-agent. The component uses a blacklist-based approach with regular expressions to identify and block dangerous shell commands (e.g., piping curl to bash). However, the regex patterns are insufficient and can be bypassed using semantically equivalent bash syntax, such as command substitution (e.g., `eval $(curl ...)`). A remote attacker can exploit this by providing a crafted prompt to the LLM agent, causing it to execute arbitrary shell commands without triggering the required human approval prompt. As of the advisory date, the vendor has not responded to the disclosure.
Affected products
- NousResearch hermes-agent up to 5157f5427f19488b31c6fdebbacd15d798ce7f63
Timeline
- 2026-04-24: disclosed: Public disclosure of the bypass and proof-of-concept via GitHub Gist.
- 2026-05-24: advisory: NVD/VulDB advisory published.