CVE-2026-9353High· 7.3▾ Twilighthermes-agent has an Injection issue
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 40.2 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 13.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.3%
A security vulnerability has been detected in NousResearch hermes-agent up to 2026.4.23. Impacted is an unknown function of the file agent/skills_guard.py of the component Skills Guard Multi-Word Prompt Handler. The manipulation of the argument THREAT_PATTERNS leads to injection. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
hermes-agent < 0.15.0Upgrade to a patched release:
hermes-agent 0.15.0Connected by shared product, vendor, weakness, or advisory.
CVE-2026-10224Medium· 5.3hermes-agent has an Uncontrolled Resource Consumption issue
CVE-2026-10223Medium· 6.3hermes-agent has an Injection issue
CVE-2026-10221High· 7.3hermes-agent has an Injection issue
CVE-2026-9368High· 7.3hermes-agent has a sandbox issue
CVE-2026-9366High· 7.3hermes-agent has an Injection issue
CVE-2026-9369Medium· 5.3hermes-agent has an Incorrect Comparison