CVE-2026-10221High· 7.3▾ Twilighthermes-agent has an Injection issue
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 40.2 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 28.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.3%
A vulnerability was identified in NousResearch hermes-agent up to 0.12.0. Affected by this vulnerability is the function _compress_context of the file run_agent.py. The manipulation leads to injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
hermes-agent <= 0.19.0Refer to the advisory for the patched release.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-10224Medium· 5.3hermes-agent has an Uncontrolled Resource Consumption issue
CVE-2026-10223Medium· 6.3hermes-agent has an Injection issue
CVE-2026-9368High· 7.3hermes-agent has a sandbox issue
CVE-2026-9366High· 7.3hermes-agent has an Injection issue
CVE-2026-9369Medium· 5.3hermes-agent has an Incorrect Comparison
CVE-2026-9353High· 7.3hermes-agent has an Injection issue