{"id":"CVE-2026-82020","title":"Hermes Agent 0.16.0 prior to 0.17.0 contains an improper path restriction vulnerability that allows attackers who can influence ingested message content to overwrite the credential store by bypassing sensitive-path guards that excluded t…","summary":"Hermes Agent 0.16.0 prior to 0.17.0 contains an improper path restriction vulnerability that allows attackers who can influence ingested message content to overwrite the credential store by bypassing sensitive-path guards that excluded t…","severity":"medium","cvss":6.8,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N","cwe":["CWE-552"],"published":"2026-08-28","updated":"2026-09-08","sourceUpdated":"2026-09-08T20:23:49.880","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-82020","references":[{"url":"https://github.com/NousResearch/hermes-agent/commit/2b67e96aec2aa2abd5e94b544cda8e564c75f9f5","label":"disclosure@vulncheck.com"},{"url":"https://github.com/NousResearch/hermes-agent/commit/da28d5d113956dcf803d5cff552a120740a96a59","label":"disclosure@vulncheck.com"},{"url":"https://github.com/NousResearch/hermes-agent/pull/45821","label":"disclosure@vulncheck.com"},{"url":"https://github.com/NousResearch/hermes-agent/releases/tag/v2026.6.19","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/hermes-agent-credential-store-overwrite-via-file-write-tool","label":"disclosure@vulncheck.com"}],"tags":["nvd"],"epss":0.00329,"epssPercentile":0.26273,"ingestedAt":"2026-09-08T21:11:12.287Z","slug":"CVE-2026-82020","body":"## Overview\n\nHermes Agent 0.16.0 prior to 0.17.0 contains an improper path restriction vulnerability that allows attackers who can influence ingested message content to overwrite the credential store by bypassing sensitive-path guards that excluded the auth.json file. Attackers can craft malicious messages directing the agent's file-write tooling to overwrite the credential store without triggering any path-based protection, enabling credential tampering or unauthorized access.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":37,"depthScoreParts":{"impact":37.4,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}