Executive brief
NousResearch hermes-agent is an AI-driven agent capable of executing code and commands. A security flaw in its code execution tool allows the AI to run arbitrary Python scripts on the host machine without the required safety approvals or manual confirmation. This could allow a remote attacker to steal sensitive credentials (like database URLs or cloud access keys) or perform destructive actions on the server where the agent is running.
Technical details
A vulnerability in the `execute_code` function within `tools/code_execution_tool.py` allows LLM-generated Python scripts to bypass the `tools/approval.py` guardrails that normally protect the terminal tool. While the agent attempts to sanitize the environment passed to the subprocess using a substring-based blocklist (`_SECRET_SUBSTRINGS`), the list is incomplete and fails to filter common sensitive variables like `DATABASE_URL` or `AWS_ACCESS_ID`. Furthermore, because the `execute_code` path does not invoke `_check_all_guards()`, an attacker can execute arbitrary Python code to read sensitive files from disk or perform system-level commands without user interaction. The issue is addressed in version 0.11.0.
Affected products
- NousResearch hermes-agent < 0.11.0
Timeline
- 2026-04-24: disclosed: Initial vulnerability report and PoC published on GitHub Gist.
- 2026-05-24: advisory: NVD published CVE-2026-9368.
- 2026-05-26: advisory: GitHub Advisory GHSA-wm96-9gfh-vvgq published.
- 2026-06-30: patched: Advisory updated to reflect patched version 0.11.0.