---
id: CVE-2026-82021
title: >-
  Hermes Agent 0.18.2 prior to 0.19.0 contains a supply chain vulnerability in
  its bundled MCP catalog that allows a remote attacker to execute arbitrary
  code by compromising a third-party upstream repository referenced via a
  mutable branc…
summary: >-
  Hermes Agent 0.18.2 prior to 0.19.0 contains a supply chain vulnerability in
  its bundled MCP catalog that allows a remote attacker to execute arbitrary
  code by compromising a third-party upstream repository referenced via a
  mutable branc…
severity: high
cvss: 8.3
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H'
cwe:
  - CWE-494
published: '2026-08-28'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T20:23:49.880'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-82021'
references:
  - url: >-
      https://github.com/NousResearch/hermes-agent/commit/9df5f879b4a5925c0f8f947e7e16ed8e845932c3
    label: disclosure@vulncheck.com
  - url: 'https://github.com/NousResearch/hermes-agent/pull/64463'
    label: disclosure@vulncheck.com
  - url: 'https://github.com/NousResearch/hermes-agent/releases/tag/v2026.7.20'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/hermes-agent-mcp-catalog-supply-chain-rce-via-mutable-branch-reference
    label: disclosure@vulncheck.com
tags:
  - nvd
epss: 0.00339
epssPercentile: 0.24601
ingestedAt: '2026-09-08T21:11:12.287Z'
---

## Overview

Hermes Agent 0.18.2 prior to 0.19.0 contains a supply chain vulnerability in its bundled MCP catalog that allows a remote attacker to execute arbitrary code by compromising a third-party upstream repository referenced via a mutable branch rather than a pinned commit SHA. An attacker who compromises the upstream repository can propagate malicious code to every host that installs the affected catalog entry, with no further action required by the operator.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
