CVE-2026-53870Medium· 5.5▾ SunlitHermes Agent creates response_store.db and webhook_subscriptions.json with world-readable permissions (mode 0o644)
▾ Sunlit zone — Low / medium · no exploitation signal
impact 30.3 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 4.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
Last analysed / modified upstream
0.1%
0.1% → 0.1%
Hermes Agent before 0.16.0 creates response_store.db and webhook_subscriptions.json with world-readable permissions (mode 0o644), exposing conversation history and HMAC secrets to local users. Attackers with local filesystem access can read these files directly to obtain sensitive data including conversation history, tool payloads, prompts, and per-route HMAC secrets.
hermes-agent < 0.16.0Upgrade to a patched release:
hermes-agent 0.16.0Connected by shared product, vendor, weakness, or advisory.
CVE-2026-53869High· 7.5Hermes Agent contains a DNS rebinding vulnerability in WebSocket endpoints that allows remote attackers to bypass Host and Origin validation
CVE-2026-10224Medium· 5.3hermes-agent has an Uncontrolled Resource Consumption issue
CVE-2026-10223Medium· 6.3hermes-agent has an Injection issue
CVE-2026-10221High· 7.3hermes-agent has an Injection issue
CVE-2026-9368High· 7.3hermes-agent has a sandbox issue
CVE-2026-9366High· 7.3hermes-agent has an Injection issue