Junglewise Threat Intelligence

CVE-2026-9368: NousResearch hermes-agent sandbox bypass in execute_code tool

CVE-2026-9368 · Severity: high · CVSS 7.3 · Published 2026-05-24

Technologies: hermes-agent (PyPI), NousResearch Hermes Agent. Vendors: PyPI, NousResearch.

Executive brief

NousResearch hermes-agent is an AI-driven agent capable of executing code and commands. A security flaw in its code execution tool allows the AI to run arbitrary Python scripts on the host machine without the required safety approvals or manual confirmation. This could allow a remote attacker to steal sensitive credentials (like database URLs or cloud access keys) or perform destructive actions on the server where the agent is running.

Technical details

A vulnerability in the `execute_code` function within `tools/code_execution_tool.py` allows LLM-generated Python scripts to bypass the `tools/approval.py` guardrails that normally protect the terminal tool. While the agent attempts to sanitize the environment passed to the subprocess using a substring-based blocklist (`_SECRET_SUBSTRINGS`), the list is incomplete and fails to filter common sensitive variables like `DATABASE_URL` or `AWS_ACCESS_ID`. Furthermore, because the `execute_code` path does not invoke `_check_all_guards()`, an attacker can execute arbitrary Python code to read sensitive files from disk or perform system-level commands without user interaction. The issue is addressed in version 0.11.0.

Affected products

  • NousResearch hermes-agent < 0.11.0

Timeline

  • 2026-04-24: disclosed: Initial vulnerability report and PoC published on GitHub Gist.
  • 2026-05-24: advisory: NVD published CVE-2026-9368.
  • 2026-05-26: advisory: GitHub Advisory GHSA-wm96-9gfh-vvgq published.
  • 2026-06-30: patched: Advisory updated to reflect patched version 0.11.0.

References

Related threats