CVE-2026-9369Medium· 5.3▾ Sunlithermes-agent has an Incorrect Comparison
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.2 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 13.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.2%
0.2% → 0.2%
A security flaw has been discovered in NousResearch hermes-agent 2026.4.23. Affected is the function _discover_dashboard_plugins of the file hermes_cli/web_server.py of the component CLI web-dashboard Interface. Performing a manipulation of the argument HERMES_ENABLE_PROJECT_PLUGINS results in incorrect comparison. The attack is only possible with local access. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
hermes-agent < 0.15.0Upgrade to a patched release:
hermes-agent 0.15.0Connected by shared product, vendor, weakness, or advisory.
CVE-2026-10224Medium· 5.3hermes-agent has an Uncontrolled Resource Consumption issue
CVE-2026-10223Medium· 6.3hermes-agent has an Injection issue
CVE-2026-10221High· 7.3hermes-agent has an Injection issue
CVE-2026-9368High· 7.3hermes-agent has a sandbox issue
CVE-2026-9366High· 7.3hermes-agent has an Injection issue
CVE-2026-9353High· 7.3hermes-agent has an Injection issue