CVE-2026-53869High· 7.5▾ TwilightHermes Agent contains a DNS rebinding vulnerability in WebSocket endpoints that allows remote attackers to bypass Host and Origin validation
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 4.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
Last analysed / modified upstream
0.6%
Hermes Agent before 0.16.0 contains a DNS rebinding vulnerability in WebSocket endpoints that allows remote attackers to bypass Host and Origin validation. FastAPI HTTP middleware does not execute for WebSocket upgrade requests on /api/pty, /api/ws, /api/pub, and /api/events endpoints, enabling attackers to exploit DNS rebinding and inject malicious commands or read terminal output.
hermes-agent < 0.16.0Upgrade to a patched release:
hermes-agent 0.16.0Connected by shared product, vendor, weakness, or advisory.
CVE-2026-53870Medium· 5.5Hermes Agent creates response_store.db and webhook_subscriptions.json with world-readable permissions (mode 0o644)
CVE-2026-10224Medium· 5.3hermes-agent has an Uncontrolled Resource Consumption issue
CVE-2026-10223Medium· 6.3hermes-agent has an Injection issue
CVE-2026-10221High· 7.3hermes-agent has an Injection issue
CVE-2026-9368High· 7.3hermes-agent has a sandbox issue
CVE-2026-9366High· 7.3hermes-agent has an Injection issue