Junglewise Threat Intelligence

CVE-2026-9369: NousResearch hermes-agent incorrect comparison in web_server.py

CVE-2026-9369 · Severity: medium · CVSS 5.3 · Published 2026-05-24

Technologies: hermes-agent (PyPI), NousResearch Hermes Agent. Vendors: PyPI, NousResearch.

Executive brief

NousResearch hermes-agent is a tool used for managing AI agents and their web-based dashboards. A security flaw allows malicious code to run on a user's computer if they open a compromised project folder, even if they have explicitly disabled plugin support in their settings. This could allow an attacker to gain control over the user's local environment and access sensitive data.

Technical details

A vulnerability exists in the `_discover_dashboard_plugins` function within `hermes_cli/web_server.py` due to an incorrect comparison of the `HERMES_ENABLE_PROJECT_PLUGINS` environment variable. The application uses `os.environ.get()` instead of a boolean-aware utility, causing non-empty strings like "false" or "0" to be evaluated as truthy. An attacker can exploit this by placing a malicious `manifest.json` and Python payload within a repository's `.hermes/plugins/` directory. When a user starts the web dashboard (`hermes --web`) while inside the malicious repository, the agent automatically imports and executes the attacker's code. This bypasses intended security opt-out configurations and leads to local code execution. The issue is addressed in version 0.15.0.

Affected products

  • NousResearch hermes-agent < 0.15.0

Timeline

  • 2026-04-24: disclosed: Initial discovery and PoC report created
  • 2026-05-24: advisory: NVD publication of CVE-2026-9369
  • 2026-05-26: advisory: GitHub Advisory published
  • 2026-06-30: patched: GitHub Advisory updated with patch information

References

Related threats