CyberRota Analysis
AI-GeneratedA vulnerability in the Quick Command Handler of NousResearch hermes-agent versions up to 2026.6.5 allows for incorrect authorization due to issues in the _check_slash_access function, which can be exploited remotely. This could lead to unauthorized access to sensitive functionalities within the application. Organizations using affected versions should prioritize patching this vulnerability to mitigate potential exploitation risks.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
A vulnerability was detected in NousResearch hermes-agent up to 2026.6.5. Affected by this issue is the function _check_slash_access of the file gateway/run.py of the component Quick Command Handler. The manipulation results in incorrect authorization. The attack can be launched remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.