Vendor
NousResearch vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 35 vulnerabilities in NousResearch: 0 in the last 7 days and 17 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-85107, was published on 3 September 2026. 1 technology has a page of its own.
- Last 7 days
- 0
- Last 90 days
- 17
- Critical, all time
- 0
- Exploited in the wild
- 0
About NousResearch
NousResearch is an open-source collective focused on the development and fine-tuning of large language models.
NousResearch technologies
Latest NousResearch vulnerabilities
- CVE-2026-85107: NousResearch hermes-agent resource exhaustion in resourceBufferFromUrlmediumCVSS 4.3EPSS 0.5%
- CVE-2026-85106: NousResearch hermes-agent server-side request forgery in Link Title FetchmediumCVSS 6.3EPSS 0.4%
- CVE-2026-85105: NousResearch hermes-agent authorization bypass in Session ManagementhighCVSS 7.3EPSS 0.5%
- CVE-2026-84289: NousResearch hermes-agent denial of service in MCP ToolmediumCVSS 4.3EPSS 0.5%
- CVE-2026-84288: NousResearch hermes-agent denial of service in ACP Prompt WorkflowmediumCVSS 4.3EPSS 0.5%
- CVE-2026-84287: NousResearch hermes-agent denial of service in session chatmediumCVSS 4.3EPSS 0.5%
- CVE-2026-18775: NousResearch hermes-agent SSRF in browser toolingmediumCVSS 6.3EPSS 0.4%
- CVE-2026-18774: NousResearch hermes-agent server-side request forgery in image providermediumCVSS 6.3EPSS 0.4%
- CVE-2026-18773: NousResearch hermes-agent authorization bypass in slash commandsmediumCVSS 6.3EPSS 0.4%
- CVE-2026-17432: NousResearch hermes-agent authorization bypass in SimpleX GatewaymediumCVSS 5
- CVE-2026-15311: NousResearch hermes-agent XSS in Matrix AdapterlowCVSS 3.5
- CVE-2026-14783: NousResearch hermes-agent path traversal in skill_viewmediumCVSS 4.3
- CVE-2026-14628: NousResearch hermes-agent path traversal in Live Webhook EndpointmediumCVSS 5.3
- CVE-2026-14627: NousResearch hermes-agent improper authentication in Discord integrationmediumCVSS 5.6
- CVE-2026-14626: NousResearch hermes-agent denial of service in AIAgent.run_conversationmediumCVSS 4.3
- CVE-2026-14625: NousResearch hermes-agent security scanner bypass in gateway shell executionmediumCVSS 6.3
- CVE-2026-14617: NousResearch hermes-agent information disclosure via case-sensitive tag matchinglowCVSS 3.1
- CVE-2026-53870: NousResearch Hermes Agent sensitive information disclosure via world-readable filesmediumCVSS 5.5EPSS 0.1%
- CVE-2026-53869: NousResearch Hermes Agent DNS rebinding in WebSocket endpointshighCVSS 7.5EPSS 0.8%
- CVE-2026-11461: NousResearch hermes-agent authorization bypass in resolve_session_by_titlemediumCVSS 6.3
- CVE-2026-10548: NousResearch hermes-agent improper authentication in Credential PoolmediumCVSS 5.3
- CVE-2026-10224: NousResearch hermes-agent denial of service in Feishu webhook handlermediumCVSS 5.3EPSS 0.4%
- CVE-2026-10223: NousResearch hermes-agent prompt injection bypass in memory_tool.pymediumCVSS 6.3EPSS 0.2%
- CVE-2026-10222: NousResearch hermes-agent injection in _sanitize_env_linesmediumCVSS 5.6EPSS 0.3%
- CVE-2026-10221: NousResearch hermes-agent prompt injection in context compressionhighCVSS 7.3EPSS 0.3%
Most severe NousResearch vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-53869: NousResearch Hermes Agent DNS rebinding in WebSocket endpointshighCVSS 7.5EPSS 0.8%
- CVE-2026-9367: NousResearch hermes-agent OS command injection in terminal_toolhighCVSS 7.3EPSS 1.0%
- CVE-2026-9368: NousResearch hermes-agent sandbox bypass in execute_code toolhighCVSS 7.3EPSS 0.6%
- CVE-2026-9366: NousResearch hermes-agent prompt injection in prompt_builder.pyhighCVSS 7.3EPSS 0.5%
- CVE-2026-9353: NousResearch hermes-agent prompt injection bypass in Skills GuardhighCVSS 7.3EPSS 0.5%
- CVE-2026-85105: NousResearch hermes-agent authorization bypass in Session ManagementhighCVSS 7.3EPSS 0.5%
- CVE-2026-10221: NousResearch hermes-agent prompt injection in context compressionhighCVSS 7.3EPSS 0.3%
- CVE-2026-9350: NousResearch hermes-agent authorization bypass in Batch RunnerhighCVSS 7.3EPSS 0.0%
- CVE-2026-10220: NousResearch hermes-agent prompt injection bypass in skills_tool.pyhighCVSS 7.3
- CVE-2026-9351: NousResearch hermes-agent path traversal in read_file toolmediumCVSS 6.5EPSS 0.1%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 5 | 0 | |
| 6 Jul 2026 | 2 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 1 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 3 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 6 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/vendors/nousresearch.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "NousResearch vulnerabilities", https://junglewise.ai/threats/vendors/nousresearch, 26 September 2026.