Technology · PyPI
hermes-agent (PyPI) vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 10 vulnerabilities in hermes-agent (PyPI): 0 in the last 7 days and 0 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-53870, was published on 17 June 2026.
- Last 7 days
- 0
- Last 90 days
- 0
- Critical, all time
- 0
- Exploited in the wild
- 0
Latest hermes-agent (PyPI) vulnerabilities
- CVE-2026-53870: NousResearch Hermes Agent sensitive information disclosure via world-readable filesmediumCVSS 5.5EPSS 0.1%
- CVE-2026-53869: NousResearch Hermes Agent DNS rebinding in WebSocket endpointshighCVSS 7.5EPSS 0.8%
- CVE-2026-10224: NousResearch hermes-agent denial of service in Feishu webhook handlermediumCVSS 5.3EPSS 0.4%
- CVE-2026-10223: NousResearch hermes-agent prompt injection bypass in memory_tool.pymediumCVSS 6.3EPSS 0.2%
- CVE-2026-10222: NousResearch hermes-agent injection in _sanitize_env_linesmediumCVSS 5.6EPSS 0.3%
- CVE-2026-10221: NousResearch hermes-agent prompt injection in context compressionhighCVSS 7.3EPSS 0.3%
- CVE-2026-9369: NousResearch hermes-agent incorrect comparison in web_server.pymediumCVSS 5.3EPSS 0.3%
- CVE-2026-9368: NousResearch hermes-agent sandbox bypass in execute_code toolhighCVSS 7.3EPSS 0.6%
- CVE-2026-9366: NousResearch hermes-agent prompt injection in prompt_builder.pyhighCVSS 7.3EPSS 0.5%
- CVE-2026-9353: NousResearch hermes-agent prompt injection bypass in Skills GuardhighCVSS 7.3EPSS 0.5%
Most severe hermes-agent (PyPI) vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-53869: NousResearch Hermes Agent DNS rebinding in WebSocket endpointshighCVSS 7.5EPSS 0.8%
- CVE-2026-9368: NousResearch hermes-agent sandbox bypass in execute_code toolhighCVSS 7.3EPSS 0.6%
- CVE-2026-9366: NousResearch hermes-agent prompt injection in prompt_builder.pyhighCVSS 7.3EPSS 0.5%
- CVE-2026-9353: NousResearch hermes-agent prompt injection bypass in Skills GuardhighCVSS 7.3EPSS 0.5%
- CVE-2026-10221: NousResearch hermes-agent prompt injection in context compressionhighCVSS 7.3EPSS 0.3%
- CVE-2026-10223: NousResearch hermes-agent prompt injection bypass in memory_tool.pymediumCVSS 6.3EPSS 0.2%
- CVE-2026-10222: NousResearch hermes-agent injection in _sanitize_env_linesmediumCVSS 5.6EPSS 0.3%
- CVE-2026-53870: NousResearch Hermes Agent sensitive information disclosure via world-readable filesmediumCVSS 5.5EPSS 0.1%
- CVE-2026-10224: NousResearch hermes-agent denial of service in Feishu webhook handlermediumCVSS 5.3EPSS 0.4%
- CVE-2026-9369: NousResearch hermes-agent incorrect comparison in web_server.pymediumCVSS 5.3EPSS 0.3%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 | |
| 28 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/pypi-hermes-agent.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "hermes-agent (PyPI) vulnerabilities", https://junglewise.ai/threats/technologies/pypi-hermes-agent, 28 September 2026.